Impact
An out‑of‑bounds read bug exists in Netcore NR255‑V firmware 1.5.130703. When a truncated firmware image is uploaded through the put_file_cgi.c interface, the mtd_write pre‑flash validation routine performs reads beyond the intended buffer boundaries. The resulting memory disclosure can leak sensitive data from the device, although the vulnerability does not allow arbitrary code execution or denial of service. The CVSS score of 7.1 reflects the medium‑to‑high impact on confidentiality.
Affected Systems
The bug affects Netcore NR255‑V routers that are running firmware version 1.5.130703. No other firmware revisions or router models are specifically listed as impacted in the available information.
Risk and Exploitability
The EPSS score is below 1%’s exploitation is currently expected to be rare. Attackers would need to submit a short, truncated firmware image to the router’s administrative web interface, which typically requires privileged access. The observation that most firmware upload mechanisms require authentication leads to the inference that an attacker must possess valid credentials or the device must be left with default settings; if authenticated, the out‑of‑bounds read could expose memory contents, but no evidence of additional payload execution or system compromise is reported.
OpenCVE Enrichment