Netcore
Netcore Nr255-v: vulnerabilidades y CVE
Netcore Nr255-v tiene 21 vulnerabilidades publicadas, 21 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses21
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-76873 | Media (5.1) | 0.24% | — | 15 sept 2026 | Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in the DHCP dynamic IP display and ARP bind list display components handling hostname fields. A LAN-based attacker can inject… |
| CVE-2026-76872 | Media (5.1) | 0.24% | — | 15 sept 2026 | Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in DHCP static IP and IP ACL management pages, including dhcp_add_staticip_cgi, dhcp_staticip_show_cgi, ip_acl_set_cgi, and… |
| CVE-2026-76870 | Alta (7.1) | 0.40% | — | 15 sept 2026 | Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtd_write pre-flash validation routine triggered by short firmware uploads. Attackers can upload a truncated firmware image via… |
| CVE-2026-76869 | Alta (8.6) | 0.57% | — | 15 sept 2026 | Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in reboot_timer_set.cgi caused by improper sscanf token parsing. Attackers can exploit this flaw by submitting crafted input to the affected… |
| CVE-2026-76868 | Media (6.9) | 0.47% | — | 15 sept 2026 | Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in route_policy_add.cgi caused by a missing exit_port parameter. Attackers can send requests lacking the exit_port field to trigger… |
| CVE-2026-76867 | Media (5.1) | 0.24% | — | 15 sept 2026 | Netcore NR255-V firmware version 1.5.130703 contains a stored cross-site scripting vulnerability in routing and NAT configuration CGI components including routing_tab_add_cgi, routing_table_list_show_cgi,… |
| CVE-2026-76865 | Media (6.9) | 0.47% | — | 15 sept 2026 | Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in the QoS setter CGI handlers filter_conn_del_cgi.c and gre_prio_set_cgi.c due to unchecked atoi() results. An attacker can trigger… |
| CVE-2026-76863 | Media (5.3) | 0.28% | — | 15 sept 2026 | Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the mod_qos_bandwidth plan.json handling within filter_conns_dump_cgi.c and IGD_CgiCall.c. Authenticated users with broad… |
| CVE-2026-76862 | Alta (8.7) | 0.55% | — | 15 sept 2026 | Netcore NR255-V version 1.5.130703 contains an os command argument injection vulnerability in the Nettools tcpdump launch paths, including ntools_start_set_cgi, ntools_tcpdump_start_set_cgi, exe_default, and ntools_proc… |
| CVE-2026-76860 | Alta (8.7) | 0.55% | — | 15 sept 2026 | Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in wake_up_set.cgi caused by unbounded tokenization of MAC and ID input. Attackers can supply crafted MAC and ID values to the affected endpoint… |
| CVE-2026-76859 | Alta (7.1) | 0.36% | — | 15 sept 2026 | Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the user_pass_show.cgi component. Low-privilege attackers can exploit this flaw via ui_config_2.xml and misc.js to disclose… |
| CVE-2026-76858 | Media (4.8) | 0.30% | — | 15 sept 2026 | Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in ddns_wan_list_show.cgi caused by unsafe eval() handling of DDNS data. Attackers can inject malicious script through the DDNS… |
| CVE-2026-76857 | Alta (7.1) | 0.36% | — | 15 sept 2026 | Netcore NR255-V firmware version 1.5.130703 contains a sensitive information disclosure vulnerability in the ddns_wan_list_show.cgi endpoint and related DDNSset_cgi, IGD_GetCgiHandler, and IGD_CgiCall components.… |
| CVE-2026-76855 | Alta (7.1) | 0.39% | — | 15 sept 2026 | Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the audit endpoints handled by l7_web_auth_log_dump_cgi.c, audit_get_cgi.c, and mod_dispatch_auth/plan.json. Attackers can… |
| CVE-2026-76854 | Alta (7.1) | 0.39% | — | 15 sept 2026 | Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l7_web_auth_user_show.cgi related to captive-portal credential handling. Attackers can query this component to obtain… |
| CVE-2026-92257 | Media (5.1) | 0.24% | — | 15 sept 2026 | Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages that use eval() sinks, affecting the call board text and policy group handling components. Attackers… |
| CVE-2026-92255 | Media (5.3) | 0.35% | — | 15 sept 2026 | Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by improper use of a string handling API. Attackers can trigger an unterminated buffer over-read by… |
| CVE-2026-76871 | Alta (7.1) | 0.36% | — | 15 sept 2026 | Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in mod_vpn_remote/plan.json, pptpd_user_show.cgi, pptp_client_config_show.cgi, and l2tpd_user_show.cgi. Attackers can leverage… |
| CVE-2026-76866 | Alta (8.6) | 0.57% | — | 15 sept 2026 | Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplied DDNS input in DDNSset_cgi.c and related ddns_Proc.c components, enabling os command argument injection. Attackers can… |
| CVE-2026-76861 | Alta (8.7) | 0.68% | — | 15 sept 2026 | Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in ntools_tcpdump_start_set.cgi caused by an unsized sprintf call when processing form values. An attacker can submit crafted input to this cgi… |
| CVE-2026-76856 | Alta (7) | 0.19% | — | 15 sept 2026 | Netcore NR255-V firmware version 1.5.130703 contains a cross-site request forgery vulnerability affecting the wan_config_set_cgi, wan_num_set_cgi, and lan_ip_change_cgi endpoints. Attackers can craft forged requests to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.