CVE-2026-76870
nicheOut-of-Bounds Read in Netcore NR255-V Firmware Upload Validation
Netcore NR255-V router firmware version 1.5.130703 contains an out-of-bounds read (CWE-125) in the mtd_write pre-flash validation routine, triggered when a short or truncated firmware image is uploaded through the put_file_cgi.c upload handler. An attacker with low privileges (an authenticated management-interface user) can upload a malformed image, causing out-of-bounds reads across main.c, check_image_uuid.c, and oemMD5Update.c. The primary impact is denial of service — the device can crash or become unavailable (VA:H in the CVSS 4.0 vector, scored 7.1 high) — with only low impact on confidentiality, so limited information disclosure from out-of-bounds memory is possible but not the main risk. Affected deployments are organizations still running the NR255-V enterprise router on firmware 1.5.130703, a version string suggesting 2013-era code that is likely end-of-life. No public proof of concept exists and the CVE is not in the CISA KEV catalog, so exploitation status is none known.
What to do: Restrict the router's management interface to trusted internal networks and ensure firmware-upload endpoints (put_file_cgi) are not reachable from the WAN. Contact Netcore for a fixed firmware release, and given the 2013-era firmware version, plan to replace the device if no patch is available. Monitor logs for failed or aborted firmware flash attempts and unexpected reboots, which would indicate someone probing this flaw.
| Netcore NR255-V | 1.5.130703 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtd_write pre-flash validation routine triggered by short firmware uploads. Attackers can upload a truncated firmware image via put_file_cgi.c to trigger out-of-bounds reads across main.c, check_image_uuid.c, and oemMD5Update.c.
- Weakness
- CWE-125
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.