Out-of-Bounds Read Vulnerability in Netcore NR255-V Router
CVE-2026-76870

7.1HIGH

Key Information:

Vendor

Netcore

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-76870?

The Netcore NR255-V router, specifically version 1.5.130703, is vulnerable to an out-of-bounds read due to flawed pre-flash validation during firmware updates. This vulnerability is triggered by uploading a truncated firmware image, which can result in unintended memory access across multiple code files, including main.c, check_image_uuid.c, and oemMD5Update.c. Attackers exploiting this flaw may gain unauthorized access to critical memory content, threatening the integrity and security of device operations.

Affected Version(s)

NR255-V 1.5.130703

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zhou Ao
Yin Luxing
Jiang Yuxuan
Liu Xin
@Nebusec
.