Junglewise Threat Intelligence

CVE-2026-76870: Netcore NR255-V out-of-bounds read in firmware upload validation

CVE-2026-76870 · Severity: high · CVSS 7.1 · Published 2026-09-15

Technologies: Netcore NR255-V. Vendors: Netcore.

Executive brief

The Netcore NR255-V is a wireless router used in residential and small business networks. This vulnerability allows an authenticated attacker to upload a truncated firmware image, causing the device to read beyond allocated memory boundaries during validation. A successful exploit could lead to information disclosure or unexpected device behavior, potentially disrupting network connectivity.

Technical details

This is an out-of-bounds read (CWE-125) vulnerability in the mtd_write pre-flash validation routine of the Netcore NR255-V firmware. The vulnerability is triggered when a truncated firmware image is uploaded via the put_file_cgi.c interface, causing out-of-bounds memory reads across multiple validation components (main.c, check_image_uuid.c, and oemMD5Update.c). The attack requires network access and authentication (PR:L per CVSS vector), with no user interaction needed. An attacker can achieve information disclosure and potentially cause availability impact by inducing invalid device behavior. Patches or fixes for this vulnerability are not mentioned in available sources.

Affected products

  • Netcore NR255-V 1.5.130703

Timeline

  • 2026-09-04: disclosed: Vulnerability publicly disclosed on GitHub
  • 2026-09-15: advisory: CVE-2026-76870 published and advisory released

References

Related threats