Description
Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in the QoS setter CGI handlers filter_conn_del_cgi.c and gre_prio_set_cgi.c due to unchecked atoi() results. An attacker can trigger the flaw by supplying crafted input to these handlers, causing a denial of service.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

Netcore NR255‑V firmware 1.5.130703 contains a null pointer dereference flaw in the QoS setter CGI handlers (filter_conn_del_cgi.c and gre_prio_set_cgi.c). The issue arises from unchecked results of atoi() on input provided by an attacker. When triggered, the flaw causes an unhandled crash of the device’s web service, leading to a denial of service for the router’s interface and any network services that depend on it.

Affected Systems

The vulnerability is documented only for the Netcore NR255‑V model running firmware version 1.5.130703. No other Netcore firmware revisions or products have been identified as affected in the CVE entry.

Risk and Exploitability

The CVSS score of 6.9 classifies the flaw as moderate severity. An EPSS score of less than 1% indicates a very low probability of active exploitation at present. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not been widely abused. An attacker would need to reach the device’s CGI endpoints over the network and supply malformed numeric parameters, which is a straightforward remote attack. Given the low EPSS, the overall risk is moderate, but timely remediation is recommended to eliminate the denial of service vector.

Generated by OpenCVE AI on September 16, 2026 at 20:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the Netcore support website for any firmware update that addresses the null pointer dereference in the QoS setter handlers.
  • If an update is not yet available, restrict or block external access to the affectedgigi) using network firewalls or ACLs to prevent crafted requests.
  • Disable QoS configuration functions on the device if they are not required for network operation.
  • Monitor device logs for unexpected POST or GET requests to the QoS CGI handlers and investigate any anomalies.

Generated by OpenCVE AI on September 16, 2026 at 20:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in the QoS setter CGI handlers filter_conn_del_cgi.c and gre_prio_set_cgi.c due to unchecked atoi() results. An attacker can trigger the flaw by supplying crafted input to these handlers, causing a denial of service.
Title Netcore NR255-V 1.5.130703 NULL Pointer Dereference via Unchecked atoi() in QoS Setter Handlers
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-16T19:31:50.392Z

Reserved: 2026-08-19T21:47:08.936Z

Link: CVE-2026-76865

cve-icon Vulnrichment

Updated: 2026-09-16T19:31:43.130Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T22:17:01.160

Modified: 2026-09-16T20:17:30.640

Link: CVE-2026-76865

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T21:00:08Z

Weaknesses