CVE-2026-76862
nicheArgument Injection Leads to OS Command Execution in Netcore NR255-V Nettools
Netcore NR255-V router firmware version 1.5.130703 contains an OS command argument injection vulnerability (CWE-88) in the device's Nettools tcpdump launch paths, specifically the ntools_start_set_cgi, ntools_tcpdump_start_set_cgi, exe_default, and ntools_proc components. An attacker with low privileges (per the CVSS 4.0 vector, PR:L) can supply crafted arguments to these tcpdump launch routines, which are passed unsafely to the underlying system command and allow arbitrary commands to be manipulated and executed on the router. Successful exploitation gives the attacker high-impact control over the device's confidentiality, integrity, and availability (VC:H/VI:H/VA:H), effectively full compromise of the router. Organizations running the NR255-V at the affected firmware version with the web management interface reachable are exposed. No public proof-of-concept is known and the CVE is not on the CISA KEV list, so exploitation is currently none known.
What to do: Contact Netcore for a fixed firmware version, as no patched release is identified in the disclosure. Until then, remove the router's management interface from the internet and restrict administrative access to a trusted internal network or VPN, and minimize the number of low-privilege accounts that can reach the Nettools/tcpdump CGI pages. Monitor device logs for unexpected tcpdump processes or administrative sessions hitting ntools_start_set_cgi, ntools_tcpdump_start_set_cgi, and related endpoints.
| Netcore NR255-V | 1.5.130703 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Netcore NR255-V version 1.5.130703 contains an os command argument injection vulnerability in the Nettools tcpdump launch paths, including ntools_start_set_cgi, ntools_tcpdump_start_set_cgi, exe_default, and ntools_proc components. Attackers can inject crafted arguments into these tcpdump launch routines to manipulate executed system commands on the device.
- Weakness
- CWE-88
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.