ZeroHour

CVE-2026-76866

niche

Root-level argument injection in Netcore NR255-V router DDNS settings

CVSS 4.0
8.6 high
EPSS
Published
()
Modified
AI analysis

Netcore NR255-V firmware version 1.5.130703 constructs command lines that run as root using unquoted, unsanitized user-supplied DDNS configuration fields in DDNSset_cgi.c and related ddns_Proc.c components. An authenticated attacker with administrator access to the router's web management interface can submit crafted DDNS parameters that inject additional command arguments, which are then executed with root privileges. Successful exploitation gives full control of the device, allowing firewall rule changes, traffic interception, and persistence on the router. Only NR255-V units running firmware 1.5.130703 are confirmed affected. There is no evidence of in-the-wild exploitation, no public PoC, and the CVE is not in CISA's KEV catalog.

What to do: Restrict the router's web management interface to the LAN or a trusted management VPN segment and never expose it directly to the internet. Contact Netcore for a fixed firmware release, since no patched version is confirmed in the disclosure. Review DDNS settings and admin account credentials for unauthorized changes, and consider retiring this legacy model if vendor support has ended.

Affected
Netcore NR255-V routerfirmware 1.5.130703
Estimated exposure
nichelikely on the order of hundreds to low thousands of exposed devices (estimate) — The NR255-V is a legacy Netcore enterprise/VPN router primarily distributed in Asia with no model-specific install counts or public scan figures available, so this is a deployment-pattern inference rather than a measured count.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplied DDNS input in DDNSset_cgi.c and related ddns_Proc.c components, enabling os command argument injection. Attackers can exploit the unsanitized parameters to inject additional command arguments executed with root privileges.

Weakness
CWE-88
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.