GHSA-3f5g-mqj3-72gqMediumCVSS 4.9
Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in the QoS...
🔗 CVE IDs covered (1)
📋 Description
Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in the QoS setter CGI handlers filter_conn_del_cgi.c and gre_prio_set_cgi.c due to unchecked atoi() results. An attacker can trigger the flaw by supplying crafted input to these handlers, causing a denial of service.
🔗 References (4)
- https://nvd.nist.gov/vuln/detail/CVE-2026-76865
- https://github.com/draw-ctf/netcore-router-public-refs/blob/main/2026.08.19-netcore-nr255v-null-deref-atoi.md
- https://www.vulncheck.com/advisories/netcore-nr255-v-1.5.130703-null-pointer-dereference-via-unchecked-atoi-in-qos-setter-handlers
- https://github.com/advisories/GHSA-3f5g-mqj3-72gq