CVE-2026-76868

Summary

Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in route_policy_add.cgi caused by a missing exit_port parameter. Attackers can send requests lacking the exit_port field to trigger the null pointer dereference, resulting in a denial of service.

Affected Software

VendorProductVersion RangeStatus
NetcoreNR255-V1.5.130703affected

Weaknesses

  • CWE-476: NULL Pointer Dereference

References