Executive brief
Netcore NR255-V is a residential wireless router. A vulnerability in its ARP filtering configuration handler allows an authenticated attacker to read beyond buffer boundaries in device memory. This could expose sensitive information stored in adjacent memory regions, potentially including credentials, keys, or other confidential data.
Technical details
The vulnerability is an out-of-bounds read (CWE-125) in the filter_arp_put_file.cgi component, triggered by improper use of string handling APIs that fail to properly validate buffer boundaries. An attacker with valid login credentials can craft a malicious ARP filter import request to trigger an unterminated buffer over-read, exposing adjacent memory contents. The attack requires network reachability to the router's management interface and prior authentication. No patch availability is documented in the advisory as of the publication date.
Affected products
- Netcore NR255-V 1.5.130703
Timeline
- 2026-09-04: disclosed
- 2026-09-15: advisory