PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-92255 Netcore CVE debrief

CVE-2026-92255 debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T22:17:04.360Z and has not been modified since then. The NVD entry is currently Received. The vulnerability is an out-of-bounds read issue in filter_arp_put_file.cgi caused by improper use of a string handling API in Netcore NR255-V version 1.5.130703. This could potentially expose adjacent memory contents. Defenders should assess exposure and prioritize remediation due to the MEDIUM severity vulnerability. The CVE record and NVD entry provide details on the vulnerability.

Vendor
Netcore
Product
NR255-V
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-21
Advisory published
2026-09-15
Advisory updated
2026-09-21

Who should care

Defenders responsible for Netcore NR255-V version 1.5.130703 deployments should assess exposure and prioritize remediation due to the MEDIUM severity vulnerability. This includes verifying the presence of the vulnerability, assessing potential memory disclosure, and prioritizing remediation based on the severity of the vulnerability. Security teams and vulnerability management teams should review the CVE record and NVD entry for further details.

Why it matters

CVE-2026-92255 is a MEDIUM severity vulnerability in Netcore NR255-V version 1.5.130703 that requires verification and potential remediation to prevent memory disclosure.

  • Verify vulnerability presence in Netcore NR255-V version 1.5.130703
  • Assess exposure and potential memory disclosure
  • Prioritize remediation based on MEDIUM severity

Technical summary

The CVE record describes an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by improper use of a string handling API in Netcore NR255-V version 1.5.130703. Attackers can trigger an unterminated buffer over-read by exploiting this flaw in the affected component, potentially exposing adjacent memory contents. The vulnerability has a MEDIUM severity score of 5.3. Defenders should prioritize verifying the vulnerability and assessing exposure. The affected product is Netcore NR255-V version 1.5.130703.

Defensive priority

Defenders should prioritize verifying the vulnerability in Netcore NR255-V version 1.5.130703 and assessing exposure, as the CVE record indicates a MEDIUM severity vulnerability.

Recommended defensive actions

  • Verify the vulnerability in Netcore NR255-V version 1.5.130703
  • Assess exposure and prioritize remediation
  • Monitor for potential exploitation attempts
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets
  • Plan vendor-supported updates or mitigations through normal change control

Evidence notes

The CVE record and NVD entry provide details on the out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by improper use of a string handling API in Netcore NR255-V version 1.5.130703. The vulnerability could potentially expose adjacent memory contents. Defenders should verify the presence of the vulnerability and assess exposure. The source details are limited, and further verification is required to confirm the affected scope and severity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-92255 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-92255

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-92255 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92255

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/draw-ctf/netcore-router-public-refs/blob/main/2026.08.19-netcore-nr255v-arp-import-overread.md

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/netcore-nr255-v-1.5.130703-out-of-bounds-read-in-filter-arp-put-file-cgi-via-string-api-misuse

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.