Junglewise Threat Intelligence

CVE-2026-92255: Netcore NR255-V out-of-bounds read in filter_arp_put_file.cgi

CVE-2026-92255 · Severity: medium · CVSS 5.4 · Published 2026-09-15

Technologies: Netcore NR255-V. Vendors: Netcore.

Executive brief

Netcore NR255-V is a residential wireless router. A vulnerability in its ARP filtering configuration handler allows an authenticated attacker to read beyond buffer boundaries in device memory. This could expose sensitive information stored in adjacent memory regions, potentially including credentials, keys, or other confidential data.

Technical details

The vulnerability is an out-of-bounds read (CWE-125) in the filter_arp_put_file.cgi component, triggered by improper use of string handling APIs that fail to properly validate buffer boundaries. An attacker with valid login credentials can craft a malicious ARP filter import request to trigger an unterminated buffer over-read, exposing adjacent memory contents. The attack requires network reachability to the router's management interface and prior authentication. No patch availability is documented in the advisory as of the publication date.

Affected products

  • Netcore NR255-V 1.5.130703

Timeline

  • 2026-09-04: disclosed
  • 2026-09-15: advisory

References

Related threats