Null Pointer Dereference in Netcore NR255-V QoS Setter Handlers
CVE-2026-76865

6.9MEDIUM

Key Information:

Vendor

Netcore

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-76865?

The Netcore NR255-V version 1.5.130703 contains a security vulnerability that allows an attacker to exploit a null pointer dereference in the Quality of Service (QoS) setter CGI handlers. This vulnerability arises from the unchecked results of the atoi() function in the filter_conn_del_cgi.c and gre_prio_set_cgi.c handlers. An attacker can leverage this flaw by submitting specially crafted inputs to these handlers, which can result in a denial of service, disrupting the performance of the affected system.

Affected Version(s)

NR255-V 1.5.130703

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zhou Ao
Yin Luxing
Jiang Yuxuan
Liu Xin
@Nebusec
.