Junglewise Threat Intelligence

CVE-2026-76865: Netcore NR255-V null pointer dereference in QoS handlers

CVE-2026-76865 · Severity: medium · CVSS 4.9 · Published 2026-09-15

Technologies: Netcore NR255-V. Vendors: Netcore.

Executive brief

The Netcore NR255-V is a wireless router used in home and small office networks. A flaw in its QoS (Quality of Service) configuration handlers allows a remote attacker with administrative credentials to send specially crafted requests that crash the router's web interface, causing a temporary service outage until the device is rebooted.

Technical details

The vulnerability is a null pointer dereference (CWE-476) in the QoS setter CGI handlers filter_conn_del_cgi.c and gre_prio_set_cgi.c, caused by unchecked return values from atoi() function calls. When atoi() fails to convert input strings to integers, it returns 0 without indication of failure; the subsequent code dereferences these unvalidated values without null checks. An attacker with administrative access to the router's web interface can supply malformed input to trigger the null pointer dereference, causing a denial of service. The vulnerability affects NR255-V firmware version 1.5.130703; no patch information is currently available.

Affected products

  • Netcore NR255-V 1.5.130703

Timeline

  • 2026-09-04: disclosed
  • 2026-09-15: advisory

References

Related threats