---
id: CVE-2026-76861
title: >-
  Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in
  ntools_tcpdump_start_set.cgi caused by an unsized sprintf call when processing
  form values
summary: >-
  Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in
  ntools_tcpdump_start_set.cgi caused by an unsized sprintf call when processing
  form values. An attacker can submit crafted input to this cgi endpoint to
  overflo…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-121
vendor: Netcore
product: NR255-V
affected:
  - NR255-V 1.5.130703
published: '2026-09-15'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T19:17:10.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76861'
references:
  - url: >-
      https://github.com/draw-ctf/netcore-router-public-refs/blob/main/2026.08.19-netcore-nr255v-tcpdump-overflow.md
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/netcore-nr255-v-1.5.130703-stack-based-buffer-overflow-in-ntools-tcpdump-start-set-cgi
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00676
epssPercentile: 0.50167
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-21T18:13:18.573969Z'
ingestedAt: '2026-09-15T22:45:31.288Z'
---

## Overview

Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in ntools_tcpdump_start_set.cgi caused by an unsized sprintf call when processing form values. An attacker can submit crafted input to this cgi endpoint to overflow the stack buffer and potentially execute arbitrary code.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
