CVE-2026-76861: Netcore NR255-V 1.5.130703 Stack-Based Buffer Overflow in ntools_tcpdump_start_set.cgi
Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in ntoolstcpdumpstartset.cgi caused by an unsized sprintf call when processing form values. An attacker can submit crafted input to this cgi endpoint to overflow the stack buffer and potentially execute arbitrary code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Netcore NR255-Vto a version that resolves this vulnerability.Fixed in 1.5.130703 - Compensating control
Mitigate the stack-based buffer overflow in ntools_tcpdump_start_set.cgi by restricting or blocking access to the affected CGI endpoint (ntools_tcpdump_start_set.cgi) at the network layer (e.g., firewall/ACL) until the device is remediated.
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs low-level privileges. Exploitation is network-accessible, requires no user interaction, and has low attack complexity.
What is the potential impact if exploitation succeeds?
A successful stack buffer overflow may allow arbitrary code execution. The reported impact includes high risk to confidentiality, integrity, and availability.
Which component should be prioritized for investigation?
Investigate the ntools_tcpdump_start_set.cgi endpoint on Netcore NR255-V devices running version 1.5.130703, particularly how it handles form values submitted to that CGI handler.