CVE-2026-76862
8.8Netcore · NR255-V
Netcore NR255-V version 1.5.130703 is vulnerable to OS command argument injection within its tcpdump utility components, allowing authenticated attackers to execute arbitrary system commands.
Executive summary
Netcore NR255-V routers are susceptible to remote command execution via argument injection, posing a severe risk of full device compromise to affected network environments.
Vulnerability
This flaw involves improper neutralization of argument delimiters in command paths, specifically affecting the Nettools tcpdump functionality. An authenticated attacker can leverage this to manipulate system commands, leading to unauthorized code execution with high impact on confidentiality, integrity, and availability.
Business impact
The vulnerability carries a CVSS score of 8.8, reflecting its high severity and potential for total system takeover. Successful exploitation allows an attacker to gain control over the router, which can be utilized to intercept network traffic, pivot into internal segments, or disrupt critical business communication services.
Remediation
Immediate Action: Since no official patch is currently identified, restrict administrative access to the device interface to trusted internal networks only and disable unused tcpdump or diagnostic services.
Proactive Monitoring: Audit device logs for unusual command executions, unexpected process spawns related to tcpdump, or unauthorized login attempts targeting administrative interfaces.
Compensating Controls: Deploy a network firewall or Web Application Firewall (WAF) to filter and inspect traffic destined for the router management interface, specifically looking for malicious patterns in CGI parameters.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exists as detailed in the referenced research write-up by VulnCheck and the associated GitHub repository.
Analyst recommendation
Given the high CVSS score and the public availability of technical details, this vulnerability presents a substantial risk to network infrastructure. Administrators should treat this as a priority item by limiting exposure of the management interface immediately and monitoring for vendor-supplied firmware updates or configuration workarounds.
More Netcore CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Zhou Ao, Yin Luxing, Jiang Yuxuan, Liu Xin, @Nebusec, per the CVE Program record.