ZeroHour

CVE-2026-76862

niche

Argument Injection Leads to OS Command Execution in Netcore NR255-V Nettools

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

Netcore NR255-V router firmware version 1.5.130703 contains an OS command argument injection vulnerability (CWE-88) in the device's Nettools tcpdump launch paths, specifically the ntools_start_set_cgi, ntools_tcpdump_start_set_cgi, exe_default, and ntools_proc components. An attacker with low privileges (per the CVSS 4.0 vector, PR:L) can supply crafted arguments to these tcpdump launch routines, which are passed unsafely to the underlying system command and allow arbitrary commands to be manipulated and executed on the router. Successful exploitation gives the attacker high-impact control over the device's confidentiality, integrity, and availability (VC:H/VI:H/VA:H), effectively full compromise of the router. Organizations running the NR255-V at the affected firmware version with the web management interface reachable are exposed. No public proof-of-concept is known and the CVE is not on the CISA KEV list, so exploitation is currently none known.

What to do: Contact Netcore for a fixed firmware version, as no patched release is identified in the disclosure. Until then, remove the router's management interface from the internet and restrict administrative access to a trusted internal network or VPN, and minimize the number of low-privilege accounts that can reach the Nettools/tcpdump CGI pages. Monitor device logs for unexpected tcpdump processes or administrative sessions hitting ntools_start_set_cgi, ntools_tcpdump_start_set_cgi, and related endpoints.

Affected
Netcore NR255-V1.5.130703
Estimated exposure
nichelikely on the order of hundreds to low thousands of internet-exposed NR255-V units — Netcore/Netis routers collectively appear in internet-wide scans in the tens of thousands, but the NR255-V is a legacy model that is likely only a small fraction of that installed base; no official install counts are available.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Netcore NR255-V version 1.5.130703 contains an os command argument injection vulnerability in the Nettools tcpdump launch paths, including ntools_start_set_cgi, ntools_tcpdump_start_set_cgi, exe_default, and ntools_proc components. Attackers can inject crafted arguments into these tcpdump launch routines to manipulate executed system commands on the device.

Weakness
CWE-88
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.