CVE-2026-76869
nicheStack Buffer Overflow in Netcore NR255-V Router reboot_timer_set.cgi
Netcore NR255-V router firmware version 1.5.130703 contains a stack-based buffer overflow (CWE-121) in the reboot_timer_set.cgi CGI handler, caused by improper sscanf token parsing that copies attacker-supplied tokens into a fixed-size stack buffer without adequate bounds checking. A remote attacker who can reach the device's web management interface and holds the required high (administrator-level) privileges — as reflected in the PR:H scoring metric — can submit crafted input to the endpoint to corrupt stack memory, plausibly crashing the device or achieving arbitrary code execution. Organizations running this specific firmware version on the NR255-V, particularly units with the management interface exposed to untrusted networks, are affected. The flaw carries a CVSS 4.0 base score of 8.6 (high), but there is no known public proof of concept and no evidence of exploitation in the wild; it is not on the CISA KEV list.
What to do: Contact Netcore for firmware newer than 1.5.130703, as no patched version is identified in the available data. Restrict access to the web management interface so reboot_timer_set.cgi is reachable only from trusted internal networks or a management VLAN, and enforce strong, unique administrator credentials since exploitation requires elevated privileges. Monitor device logs for unexpected reboots, crashes, or anomalous requests to reboot_timer_set.cgi as indicators of exploitation attempts.
| Netcore (Netis) NR255-V | 1.5.130703 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in reboot_timer_set.cgi caused by improper sscanf token parsing. Attackers can exploit this flaw by submitting crafted input to the affected endpoint to corrupt stack memory.
- Weakness
- CWE-121
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.