Executive brief
The Netcore NR255-V is a network router used to manage traffic and routing policies in corporate and home networks. A null pointer dereference vulnerability in its web-based route policy configuration interface allows remote attackers with administrative access to crash the router by sending specially crafted requests, causing a denial of service and network outage.
Technical details
A null pointer dereference vulnerability exists in the route_policy_add.cgi component of Netcore NR255-V version 1.5.130703. The vulnerability is triggered when an attacker sends a request to the CGI script without the required exit_port parameter, causing the application to attempt to dereference a null pointer. The attack requires administrative privileges to access the affected interface and network connectivity to the device's web management interface. Exploitation results in a denial of service condition, crashing the affected service or device. No patch information is currently available.
Affected products
- Netcore NR255-V 1.5.130703
Timeline
- 2026-09-04: disclosed
- 2026-09-15: advisory