Impact
Netcore NR255‑V firmware 1.5.130703 contains a null pointer dereference flaw in the QoS setter CGI handlers (filter_conn_del_cgi.c and gre_prio_set_cgi.c). The issue arises from unchecked results of atoi() on input provided by an attacker. When triggered, the flaw causes an unhandled crash of the device’s web service, leading to a denial of service for the router’s interface and any network services that depend on it.
Affected Systems
The vulnerability is documented only for the Netcore NR255‑V model running firmware version 1.5.130703. No other Netcore firmware revisions or products have been identified as affected in the CVE entry.
Risk and Exploitability
The CVSS score of 6.9 classifies the flaw as moderate severity. An EPSS score of less than 1% indicates a very low probability of active exploitation at present. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not been widely abused. An attacker would need to reach the device’s CGI endpoints over the network and supply malformed numeric parameters, which is a straightforward remote attack. Given the low EPSS, the overall risk is moderate, but timely remediation is recommended to eliminate the denial of service vector.
OpenCVE Enrichment