OS Command Argument Injection Vulnerability in Netcore NR255-V by Netcore
CVE-2026-76862

8.7HIGH

Key Information:

Vendor

Netcore

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-76862?

The Netcore NR255-V version 1.5.130703 is affected by an OS command argument injection vulnerability. This flaw exists within the Nettools tcpdump launch paths, specifically in components like ntools_start_set_cgi, ntools_tcpdump_start_set_cgi, exe_default, and ntools_proc. Attackers can exploit this vulnerability by injecting malicious arguments into the tcpdump launch routines, enabling them to manipulate system commands executed on the device. This poses a significant risk, potentially leading to unauthorized access or system compromise.

Affected Version(s)

NR255-V 1.5.130703

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zhou Ao
Yin Luxing
Jiang Yuxuan
Liu Xin
@Nebusec
.