Null Pointer Dereference in Netcore NR255-V Router
CVE-2026-76868
6.9MEDIUM
What is CVE-2026-76868?
The Netcore NR255-V router, specifically version 1.5.130703, is susceptible to a null pointer dereference vulnerability in the route_policy_add.cgi component. This vulnerability arises when an attacker sends a crafted request that omits the required exit_port parameter. The absence of this parameter triggers the null pointer dereference, leading to a potential denial of service condition. This issue can severely disrupt the router's functionality, making it essential for users to evaluate their systems for any possible exposures.
Affected Version(s)
NR255-V 1.5.130703
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Zhou Ao
Yin Luxing
Jiang Yuxuan
Liu Xin
@Nebusec
