Description
Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by improper use of a string handling API. Attackers can trigger an unterminated buffer over-read by exploiting this flaw in the affected component, potentially exposing adjacent memory contents.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure (out-of-bounds read)
Action: Assess Impact
AI Analysis

Impact

Netcore NR255-V firmware 1.5.130703 contains an out-of-bounds read in the filter_arp_put_file.cgi component, caused by incorrect string API usage. A malicious actor can provoke an unterminated buffer over-read, causing the router to expose memory content located immediately after the input data, which may include configuration or authentication details. The flaw does not provide direct remote code execution or privilege escalation, but it can leak sensitive data that may aid further attacks.

Affected Systems

The vulnerability is limited to Netcore devices running the NR255‑V router firmware version 1.5.130703.

Risk and Exploitability

The CVSS score of 5.3 indicates medium severity, while the EPSS score is less than 1%, indicating low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote access through the web-based CGI interface, but the precise method is not detailed in the advisory.

Generated by OpenCVE AI on September 18, 2026 at 13:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor‑issued firmware patch that removes the over-read in filter_arp_put_file.cgi (e.g., upgrade to a version later than 1.5.130703).
  • Restrict access to the router’s web management interface, allowing only trusted administrators to reach filter_arp_put_file.cgi, and consider blocking the CGI path at the network perimeter.
  • Enable detailed logging of HTTP requests to filter_arp_put_file.cgi and monitor for repeated or anomalous access patterns that may indicate exploitation attempts.

Generated by OpenCVE AI on September 18, 2026 at 13:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Netcore
Netcore nr255-v
Vendors & Products Netcore
Netcore nr255-v

Tue, 15 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by improper use of a string handling API. Attackers can trigger an unterminated buffer over-read by exploiting this flaw in the affected component, potentially exposing adjacent memory contents.
Title Netcore NR255-V 1.5.130703 Out-of-Bounds Read in filter_arp_put_file.cgi via String API Misuse
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T20:53:03.576Z

Reserved: 2026-09-15T21:09:51.279Z

Link: CVE-2026-92255

cve-icon Vulnrichment

Updated: 2026-09-21T16:22:39.812Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T22:17:04.360

Modified: 2026-09-24T21:08:55.030

Link: CVE-2026-92255

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T13:45:08Z

Weaknesses