Description
Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by improper use of a string handling API. Attackers can trigger an unterminated buffer over-read by exploiting this flaw in the affected component, potentially exposing adjacent memory contents.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure (out-of-bounds read)
Action: Assess Impact
AI Analysis

Impact

Netcore NR255-V firmware 1.5.130703 contains an out-of-bounds read in the filter_arp_put_file.cgi component, caused by incorrect string API usage. A malicious actor can provoke an unterminated buffer over-read, causing the router to expose memory content located immediately after the input data, which may include configuration or authentication details. The flaw does not provide direct remote code execution or privilege escalation, but it can leak sensitive data that may aid further attacks.

Affected Systems

The vulnerability is limited to Netcore devices running the NR255‑V router firmware version 1.5 specific revision is not confirmed to be impacted.

Risk and Exploitability

The CVSS score of 5.3 indicates medium severity, while the EPSS score of less than of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote access through the web-based CGI interface, but the precise method is not detailed in the advisory.

Generated by OpenCVE AI on September 16, 2026 at 20:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑issued firmware patch that removes the over-read in filter_arp_put_file.cgi (e.g., upgrade to a version later than 1.5.130703).
  • Restrict access to the router’s web management interface, allowing only trusted administrators to reach filter_arp_put_file.cgi, and consider blocking the CGI path at the network perimeter.
  • Enable detailed logging of HTTP requests to filter_arp_put_file.cgi and monitor for repeated or anomalous access patterns that may indicate exploitation attempts.

Generated by OpenCVE AI on September 16, 2026 at 20:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by improper use of a string handling API. Attackers can trigger an unterminated buffer over-read by exploiting this flaw in the affected component, potentially exposing adjacent memory contents.
Title Netcore NR255-V 1.5.130703 Out-of-Bounds Read in filter_arp_put_file.cgi via String API Misuse
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T21:58:03.906Z

Reserved: 2026-09-15T21:09:51.279Z

Link: CVE-2026-92255

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-15T22:17:04.360

Modified: 2026-09-15T22:17:04.360

Link: CVE-2026-92255

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T20:30:06Z

Weaknesses