Impact
Netcore NR255-V firmware 1.5.130703 contains an out-of-bounds read in the filter_arp_put_file.cgi component, caused by incorrect string API usage. A malicious actor can provoke an unterminated buffer over-read, causing the router to expose memory content located immediately after the input data, which may include configuration or authentication details. The flaw does not provide direct remote code execution or privilege escalation, but it can leak sensitive data that may aid further attacks.
Affected Systems
The vulnerability is limited to Netcore devices running the NR255‑V router firmware version 1.5 specific revision is not confirmed to be impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, while the EPSS score of less than of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote access through the web-based CGI interface, but the precise method is not detailed in the advisory.
OpenCVE Enrichment