Null Pointer Dereference in Netcore NR255-V Router
CVE-2026-76868

6.9MEDIUM

Key Information:

Vendor

Netcore

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-76868?

The Netcore NR255-V router, specifically version 1.5.130703, is susceptible to a null pointer dereference vulnerability in the route_policy_add.cgi component. This vulnerability arises when an attacker sends a crafted request that omits the required exit_port parameter. The absence of this parameter triggers the null pointer dereference, leading to a potential denial of service condition. This issue can severely disrupt the router's functionality, making it essential for users to evaluate their systems for any possible exposures.

Affected Version(s)

NR255-V 1.5.130703

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zhou Ao
Yin Luxing
Jiang Yuxuan
Liu Xin
@Nebusec
.