ZeroHour

CVE-2026-76856

Cross-Site Request Forgery in Netcore NR255-V Router Web Interface

CVSS 4.0
7.0 high
EPSS
Published
()
Modified
AI analysis

Netcore NR255-V routers running firmware 1.5.130703 contain a cross-site request forgery (CSWE-352) flaw in the web-based management interface, specifically the wan_config_set_cgi, wan_num_set_cgi, and lan_ip_change_cgi endpoints, which fail to verify that configuration-change requests were intentionally submitted by the administrator. To exploit it, an attacker hosts malicious web content and induces an authenticated admin to view it (e.g., via a link or embedded ad); the victim's browser then silently sends forged requests that modify WAN or LAN network settings without any consent prompt, since the flaw requires no attacker privileges, only user interaction (CVSS 4.0: 7.0, high; VI:H/VA:H). A successful attack can alter WAN/LAN configuration such as IP settings, effectively letting the attacker reconfigure network routing or disrupt connectivity for everything behind the router. Affected parties are anyone operating the Netcore NR255-V enterprise router on firmware 1.5.130703, a legacy build whose version string suggests a 2013 release; no other affected products or versions were identified in the data. No public proof-of-concept exists, the issue is not on CISA's KEV list, and no exploitation has been observed in the wild.

What to do: No patched firmware version is identified in the data, so restrict the router's web management interface to a trusted management VLAN or loopback access and require admins to log out immediately after making changes rather than keeping sessions open while browsing. Audit WAN/LAN settings, gateway IP, and DNS values for unauthorized modifications, and enable change alerting if available. Contact Netcore for firmware update availability or plan retirement/replacement of this 2013-era device, which is unlikely to receive ongoing security support.

Affected
Netcore NR255-V routerFirmware 1.5.130703
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Netcore NR255-V firmware version 1.5.130703 contains a cross-site request forgery vulnerability affecting the wan_config_set_cgi, wan_num_set_cgi, and lan_ip_change_cgi endpoints. Attackers can craft forged requests to trick authenticated administrators into modifying WAN or LAN network configuration settings without consent.

Weakness
CWE-352
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.