CVE-2026-92255: Netcore NR255-V 1.5.130703 Out-of-Bounds Read in filter_arp_put_file.cgi via String API Misuse
Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filterarpputfile.cgi caused by improper use of a string handling API. Attackers can trigger an unterminated buffer over-read by exploiting this flaw in the affected component, potentially exposing adjacent memory contents.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Netcore NR255-Vto a version that resolves this vulnerability.Fixed in 1.5.130703
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability has network attack vector and low privileges required. No user interaction is required.
What is the likely impact of successful exploitation?
Successful exploitation may expose adjacent memory contents through an unterminated buffer over-read. The supplied severity metrics also indicate low confidentiality and availability impact, with no integrity impact.
How can I determine whether a device is affected?
Devices running Netcore NR255-V version 1.5.130703 are identified as affected. The vulnerable component is filter_arp_put_file.cgi.