CVE-2026-76862

8.8

Netcore · NR255-V

Netcore NR255-V version 1.5.130703 is vulnerable to OS command argument injection within its tcpdump utility components, allowing authenticated attackers to execute arbitrary system commands.

Executive summary

Netcore NR255-V routers are susceptible to remote command execution via argument injection, posing a severe risk of full device compromise to affected network environments.

Vulnerability

This flaw involves improper neutralization of argument delimiters in command paths, specifically affecting the Nettools tcpdump functionality. An authenticated attacker can leverage this to manipulate system commands, leading to unauthorized code execution with high impact on confidentiality, integrity, and availability.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting its high severity and potential for total system takeover. Successful exploitation allows an attacker to gain control over the router, which can be utilized to intercept network traffic, pivot into internal segments, or disrupt critical business communication services.

Remediation

Immediate Action: Since no official patch is currently identified, restrict administrative access to the device interface to trusted internal networks only and disable unused tcpdump or diagnostic services.

Proactive Monitoring: Audit device logs for unusual command executions, unexpected process spawns related to tcpdump, or unauthorized login attempts targeting administrative interfaces.

Compensating Controls: Deploy a network firewall or Web Application Firewall (WAF) to filter and inspect traffic destined for the router management interface, specifically looking for malicious patterns in CGI parameters.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exists as detailed in the referenced research write-up by VulnCheck and the associated GitHub repository.

Analyst recommendation

Given the high CVSS score and the public availability of technical details, this vulnerability presents a substantial risk to network infrastructure. Administrators should treat this as a priority item by limiting exposure of the management interface immediately and monitoring for vendor-supplied firmware updates or configuration workarounds.

More Netcore CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Zhou Ao, Yin Luxing, Jiang Yuxuan, Liu Xin, @Nebusec, per the CVE Program record.