Junglewise Threat Intelligence

CVE-2026-76868: Netcore NR255-V null pointer dereference in route_policy_add.cgi

CVE-2026-76868 · Severity: medium · CVSS 4.9 · Published 2026-09-15

Technologies: Netcore NR255-V. Vendors: Netcore.

Executive brief

The Netcore NR255-V is a network router used to manage traffic and routing policies in corporate and home networks. A null pointer dereference vulnerability in its web-based route policy configuration interface allows remote attackers with administrative access to crash the router by sending specially crafted requests, causing a denial of service and network outage.

Technical details

A null pointer dereference vulnerability exists in the route_policy_add.cgi component of Netcore NR255-V version 1.5.130703. The vulnerability is triggered when an attacker sends a request to the CGI script without the required exit_port parameter, causing the application to attempt to dereference a null pointer. The attack requires administrative privileges to access the affected interface and network connectivity to the device's web management interface. Exploitation results in a denial of service condition, crashing the affected service or device. No patch information is currently available.

Affected products

  • Netcore NR255-V 1.5.130703

Timeline

  • 2026-09-04: disclosed
  • 2026-09-15: advisory

References

Related threats