Junglewise Threat Intelligence

CVE-2026-76860: Netcore NR255-V stack-based buffer overflow in wake_up_set.cgi

CVE-2026-76860 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Netcore NR255-V. Vendors: Netcore.

Executive brief

Netcore NR255-V is a consumer router that provides Wake-on-LAN and other management features. The wake_up_set.cgi endpoint fails to properly validate user-supplied MAC and ID parameters, allowing attackers with login access to overflow the router's memory and potentially execute arbitrary code, compromising the device's security and availability.

Technical details

The vulnerability is a stack-based buffer overflow (CWE-121) in the wake_up_set.cgi endpoint caused by unbounded tokenization of MAC address and ID parameters. An authenticated attacker can supply crafted MAC and ID values that overflow an internal buffer and corrupt program memory, potentially leading to code execution or denial of service. The attack requires network access to the router and valid credentials; no user interaction is needed once authenticated. A patch is not yet publicly documented at the advisory publication date.

Affected products

  • Netcore NR255-V 1.5.130703

Timeline

  • 2026-09-15: disclosed
  • 2026-08-19: other: Public technical reference published

References

Related threats