Cross-Site Request Forgery in Netcore NR255-V Firmware
CVE-2026-76856

7HIGH

Key Information:

Vendor

Netcore

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-76856?

The Netcore NR255-V firmware version 1.5.130703 is susceptible to a cross-site request forgery (CSRF) vulnerability. This flaw affects multiple configuration endpoints, including wan_config_set_cgi, wan_num_set_cgi, and lan_ip_change_cgi. Attackers can exploit this vulnerability to create forged requests that deceive authenticated administrators into altering WAN or LAN configuration settings without their consent. This could lead to unauthorized access and manipulation of network settings, posing significant security risks.

Affected Version(s)

NR255-V 1.5.130703

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zhou Ao
Yin Luxing
Jiang Yuxuan
Liu Xin
@Nebusec
.