PT-2026-93196 · Netcore · Nr255-V
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Netcore NR255-V version 1.5.130703
Description
An OS command argument injection flaw exists in the Nettools tcpdump launch paths. This issue affects the
ntools start set cgi, ntools tcpdump start set cgi, exe default, and ntools proc components. Attackers can inject crafted arguments into these routines to manipulate system commands executed on the device.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nr255-V