CVE-2026-76868: NULL Pointer Dereference in Netcore NR255-V
Netcore NR255-V version 1.5.130703 has a null pointer dereference vulnerability in the route_policy_add.cgi component. This occurs when a request is sent without the required exit_port parameter, causing the device to dereference a null pointer and crash, leading to denial of service.
AI Analysis
Technical Summary
CVE-2026-76868 is a null pointer dereference vulnerability in Netcore NR255-V version 1.5.130703. The flaw exists in the route_policy_add.cgi functionality, where the absence of the exit_port parameter in a request triggers a null pointer dereference. This results in a denial of service condition by crashing or destabilizing the device.
Potential Impact
Successful exploitation causes a denial of service by crashing the affected device. There is no indication of code execution or data compromise. The vulnerability requires high privileges (PR:H) and no user interaction (UI:N) is needed.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Until a patch is available, restrict access to the affected interface and monitor for suspicious requests missing the exit_port parameter.
CVE-2026-76868: NULL Pointer Dereference in Netcore NR255-V
Description
Netcore NR255-V version 1.5.130703 has a null pointer dereference vulnerability in the route_policy_add.cgi component. This occurs when a request is sent without the required exit_port parameter, causing the device to dereference a null pointer and crash, leading to denial of service.
CVSS v4.0
Score 6.9medium
Affected software
Netcore
NR255-V
pkg:github/draw-ctf/netcore-router-public-refsRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-76868 is a null pointer dereference vulnerability in Netcore NR255-V version 1.5.130703. The flaw exists in the route_policy_add.cgi functionality, where the absence of the exit_port parameter in a request triggers a null pointer dereference. This results in a denial of service condition by crashing or destabilizing the device.
Potential Impact
Successful exploitation causes a denial of service by crashing the affected device. There is no indication of code execution or data compromise. The vulnerability requires high privileges (PR:H) and no user interaction (UI:N) is needed.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Until a patch is available, restrict access to the affected interface and monitor for suspicious requests missing the exit_port parameter.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-19T21:47:08.936Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa9c06e55bf5e2cf56f8249
Added to database: 09/15/2026, 22:02:22 UTC
Last enriched: 09/15/2026, 22:25:23 UTC
Last updated: 09/16/2026, 03:17:21 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.