Null Pointer Dereference in Netcore NR255-V QoS Setter Handlers
CVE-2026-76865
6.9MEDIUM
What is CVE-2026-76865?
The Netcore NR255-V version 1.5.130703 contains a security vulnerability that allows an attacker to exploit a null pointer dereference in the Quality of Service (QoS) setter CGI handlers. This vulnerability arises from the unchecked results of the atoi() function in the filter_conn_del_cgi.c and gre_prio_set_cgi.c handlers. An attacker can leverage this flaw by submitting specially crafted inputs to these handlers, which can result in a denial of service, disrupting the performance of the affected system.
Affected Version(s)
NR255-V 1.5.130703
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Zhou Ao
Yin Luxing
Jiang Yuxuan
Liu Xin
@Nebusec
