---
id: CVE-2026-76860
title: >-
  Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in
  wake_up_set.cgi caused by unbounded tokenization of MAC and ID input
summary: >-
  Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in
  wake_up_set.cgi caused by unbounded tokenization of MAC and ID input.
  Attackers can supply crafted MAC and ID values to the affected endpoint to
  overflow the st…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-121
vendor: Netcore
product: NR255-V
affected:
  - NR255-V 1.5.130703
published: '2026-09-15'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T20:17:29.993'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76860'
references:
  - url: >-
      https://github.com/draw-ctf/netcore-router-public-refs/blob/main/2026.08.19-netcore-nr255v-wake-up-set-overflow.md
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/netcore-nr255-v-1.5.130703-stack-based-buffer-overflow-in-wake-up-set-cgi-via-mac-and-id-tokenization
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-16T19:30:40.240306Z'
ingestedAt: '2026-09-15T22:45:31.287Z'
epss: 0.00549
epssPercentile: 0.43525
---

## Overview

Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in wake_up_set.cgi caused by unbounded tokenization of MAC and ID input. Attackers can supply crafted MAC and ID values to the affected endpoint to overflow the stack buffer and corrupt program memory.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
