Out-of-Bounds Read Vulnerability in Netcore NR255-V Router
CVE-2026-76870
7.1HIGH
What is CVE-2026-76870?
The Netcore NR255-V router, specifically version 1.5.130703, is vulnerable to an out-of-bounds read due to flawed pre-flash validation during firmware updates. This vulnerability is triggered by uploading a truncated firmware image, which can result in unintended memory access across multiple code files, including main.c, check_image_uuid.c, and oemMD5Update.c. Attackers exploiting this flaw may gain unauthorized access to critical memory content, threatening the integrity and security of device operations.
Affected Version(s)
NR255-V 1.5.130703
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Zhou Ao
Yin Luxing
Jiang Yuxuan
Liu Xin
@Nebusec
