Junglewise Threat Intelligence

CVE-2026-76861: Netcore NR255-V stack buffer overflow in ntools_tcpdump_start_set.cgi

CVE-2026-76861 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Netcore NR255-V. Vendors: Netcore.

Executive brief

Netcore NR255-V is a router device used to manage network connectivity in business and home environments. A stack buffer overflow vulnerability in its web administration interface allows authenticated attackers to submit specially crafted input that crashes the router or executes malicious code with full device privileges, potentially compromising network traffic monitoring and customer data.

Technical details

A stack-based buffer overflow (CWE-121) exists in the ntools_tcpdump_start_set.cgi endpoint due to an unsized sprintf call that does not validate the length of user-supplied form values before copying them into a fixed-size stack buffer. The vulnerable code path is in ntools_tcpdump_start_set_cgi.c (at offset 0x46b3f8) and calls get_form_value.c (0x407100). Attack requires network access and authentication to the device's web interface, but no user interaction. Exploitation allows an attacker to overflow the stack buffer and achieve arbitrary code execution with the privileges of the web server process. A patch or mitigation has not been confirmed as available at this time.

Affected products

  • Netcore NR255-V 1.5.130703

Timeline

  • 2026-09-04: disclosed
  • 2026-09-15: advisory: CVE-2026-76861 published

References

Related threats