CVE-2026-76870

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
7.1
HIGH

Description

Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtd_write pre-flash validation routine triggered by short firmware uploads. Attackers can upload a truncated firmware image via put_file_cgi.c to trigger out-of-bounds reads across main.c, check_image_uuid.c, and oemMD5Update.c.

Published
September 15, 2026 10:17 PM
Last Modified
September 15, 2026 10:17 PM
Source
[email protected]

Weaknesses (CWE)

CWE-125

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.