CVE-2026-76869: Netcore NR255-V 1.5.130703 Stack-Based Buffer Overflow in reboot_timer_set.cgi
Published Sep 15, 2026
·Updated
Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in reboottimerset.cgi caused by improper sscanf token parsing. Attackers can exploit this flaw by submitting crafted input to the affected endpoint to corrupt stack memory.
Affected Software
1 affected component
Netcore NR255-V=1.5.130703
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Netcore NR255-V reboot_timer_set.cgito a version that resolves this vulnerability.Fixed in 1.5.130703
Event History
Sep 15, 2026
CVE Published
via MITRE·09:58 PM
Data Sourced
via MITRE·09:58 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is network-reachable and requires high privileges. No user interaction is required.
2
Which component handles the vulnerable input?
The affected endpoint is reboot_timer_set.cgi. Crafted input reaches improper sscanf token parsing and can corrupt stack memory.
3
What are the potential impacts of successful exploitation?
Successful exploitation may affect confidentiality, integrity, and availability at a high impact level.