ZeroHour

CVE-2026-76870

niche

Out-of-Bounds Read in Netcore NR255-V Firmware Upload Validation

CVSS 4.0
7.1 high
EPSS
Published
()
Modified
AI analysis

Netcore NR255-V router firmware version 1.5.130703 contains an out-of-bounds read (CWE-125) in the mtd_write pre-flash validation routine, triggered when a short or truncated firmware image is uploaded through the put_file_cgi.c upload handler. An attacker with low privileges (an authenticated management-interface user) can upload a malformed image, causing out-of-bounds reads across main.c, check_image_uuid.c, and oemMD5Update.c. The primary impact is denial of service — the device can crash or become unavailable (VA:H in the CVSS 4.0 vector, scored 7.1 high) — with only low impact on confidentiality, so limited information disclosure from out-of-bounds memory is possible but not the main risk. Affected deployments are organizations still running the NR255-V enterprise router on firmware 1.5.130703, a version string suggesting 2013-era code that is likely end-of-life. No public proof of concept exists and the CVE is not in the CISA KEV catalog, so exploitation status is none known.

What to do: Restrict the router's management interface to trusted internal networks and ensure firmware-upload endpoints (put_file_cgi) are not reachable from the WAN. Contact Netcore for a fixed firmware release, and given the 2013-era firmware version, plan to replace the device if no patch is available. Monitor logs for failed or aborted firmware flash attempts and unexpected reboots, which would indicate someone probing this flaw.

Affected
Netcore NR255-V1.5.130703
Estimated exposure
nichelikely under 10,000 devices, plausibly low thousands (estimate) — The NR255-V is a discontinued small-business/enterprise router whose only listed affected firmware dates to 2013, so the exposed population is expected to be small; no public scan counts or install data were available, so this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtd_write pre-flash validation routine triggered by short firmware uploads. Attackers can upload a truncated firmware image via put_file_cgi.c to trigger out-of-bounds reads across main.c, check_image_uuid.c, and oemMD5Update.c.

Weakness
CWE-125
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.