Impact
A stack-based buffer overflow exists in the wake_up_set.cgi script of Netcore NR255-V version 1.5.130703. The flaw arises from unbounded tokenization of MAC and ID input parameters, allowing an attacker to supply malicious strings that exceed the stack buffer and corrupt program memory. Based on the description, it is inferred that this memory corruption could enable an attacker to gain device control if arbitrary code execution is possible, but the CVE does not explicitly confirm that outcome.
Affected Systems
The vulnerability affects Netcore NR255-V routers running firmware version 1.5.130703. No other versions were listed as compromised, and only the NR255-V product line is impacted.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is reported as less than 1%, suggesting a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The flaw is network accessible via the wake_up_set.cgi endpoint, and an attacker must craft specific MAC and ID values to trigger the overflow. Based on the description, it is inferred that exploitation could lead to device takeover if code execution is achieved, thus the risk remains significant for exposed devices without a patch.
OpenCVE Enrichment