PT-2026-93200 · Netcore · Nr255-V

·

CVE-2026-76866

·

Published

2026-09-15

·

Updated

2026-09-21

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netcore NR255-V version 1.5.130703
Description OS command argument injection occurs because the system builds root-run command lines using unquoted user-supplied DDNS input within the DDNSset cgi.c and ddns Proc.c components. Attackers can use unsanitized parameters to inject additional command arguments that are executed with root privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76866

Affected Products

Nr255-V