Impact
A stack-based buffer overflow exists in the wake_up_set.cgi script of Netcore NR255-V version 1.5.130703. The flaw arises from unbounded tokenization of MAC and ID input parameters, allowing an attacker to supply malicious strings that exceed the stack buffer and corrupt program memory. This overflow can compromise the integrity of the device’s execution context and potentially enable arbitrary code execution, leading to full device takeover.
Affected Systems
The vulnerability affects Netcore NR255-V routers running firmware version 1.5.130703. No other versions were listed as compromised, and only the NR255-V product line is impacted.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is reported as less than 1%, suggesting a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the flaw is network accessible via the wake_up_set.cgi endpoint, and an attacker must craft specific MAC and ID values to trigger the overflow. The risk remains significant for exposed devices without a patch, and the potential for remote code execution warrants immediate attention.
OpenCVE Enrichment