CVE-2026-76866
nicheRoot-level argument injection in Netcore NR255-V router DDNS settings
Netcore NR255-V firmware version 1.5.130703 constructs command lines that run as root using unquoted, unsanitized user-supplied DDNS configuration fields in DDNSset_cgi.c and related ddns_Proc.c components. An authenticated attacker with administrator access to the router's web management interface can submit crafted DDNS parameters that inject additional command arguments, which are then executed with root privileges. Successful exploitation gives full control of the device, allowing firewall rule changes, traffic interception, and persistence on the router. Only NR255-V units running firmware 1.5.130703 are confirmed affected. There is no evidence of in-the-wild exploitation, no public PoC, and the CVE is not in CISA's KEV catalog.
What to do: Restrict the router's web management interface to the LAN or a trusted management VPN segment and never expose it directly to the internet. Contact Netcore for a fixed firmware release, since no patched version is confirmed in the disclosure. Review DDNS settings and admin account credentials for unauthorized changes, and consider retiring this legacy model if vendor support has ended.
| Netcore NR255-V router | firmware 1.5.130703 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplied DDNS input in DDNSset_cgi.c and related ddns_Proc.c components, enabling os command argument injection. Attackers can exploit the unsanitized parameters to inject additional command arguments executed with root privileges.
- Weakness
- CWE-88
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.