OS Command Argument Injection Vulnerability in Netcore NR255-V by Netcore
CVE-2026-76862
8.7HIGH
What is CVE-2026-76862?
The Netcore NR255-V version 1.5.130703 is affected by an OS command argument injection vulnerability. This flaw exists within the Nettools tcpdump launch paths, specifically in components like ntools_start_set_cgi, ntools_tcpdump_start_set_cgi, exe_default, and ntools_proc. Attackers can exploit this vulnerability by injecting malicious arguments into the tcpdump launch routines, enabling them to manipulate system commands executed on the device. This poses a significant risk, potentially leading to unauthorized access or system compromise.
Affected Version(s)
NR255-V 1.5.130703
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Zhou Ao
Yin Luxing
Jiang Yuxuan
Liu Xin
@Nebusec
