CVE-2026-76870: Netcore NR255-V 1.5.130703 Out-of-Bounds Read in mtd_write Firmware Upload Validation

Published Sep 15, 2026
·
Updated

Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtdwrite pre-flash validation routine triggered by short firmware uploads. Attackers can upload a truncated firmware image via putfilecgi.c to trigger out-of-bounds reads across main.c, checkimageuuid.c, and oemMD5Update.c.

Affected Software

1 affected component
Netcore NR255-V=1.5.130703

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Netcore NR255-V to a version that resolves this vulnerability.

    Fixed in 1.5.130703
  2. Compensating control

    Mitigate the issue by blocking or restricting access to the firmware upload endpoint implemented in put_file_cgi.c (triggering short/truncated uploads) until the vulnerable firmware upload validation routine is fixed.

Event History

Sep 15, 2026
CVE Published
via MITRE·09:58 PM
Data Sourced
via MITRE·09:58 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What level of access does an attacker need to exploit this issue?

The attack is network-accessible but requires low-privileged access. The attacker must be able to submit a truncated firmware image through the firmware upload path.

2

What operational impact is indicated by the severity vector?

The supplied vector indicates high availability impact and low confidentiality impact, with no integrity impact indicated. Exploitation can trigger out-of-bounds reads during pre-flash image validation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203