Netcore NR255-V

23 known vulnerabilities in Netcore NR255-V, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-92257 CVSS 5.1 medium Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages that use eval()…
  • CVE-2026-92256 CVSS 7.1 high NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l2tpd_config_show_cgi.c, ipsec_show_cgi.c, and…
  • CVE-2026-92255 CVSS 5.3 medium Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by improper use of a…
  • CVE-2026-76873 CVSS 5.1 medium Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in the DHCP dynamic IP display and ARP bind list…
  • CVE-2026-76872 CVSS 5.1 medium Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in DHCP static IP and IP ACL management pages…
  • CVE-2026-76871 CVSS 7.1 high Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in mod_vpn_remote/plan.json…
  • CVE-2026-76870 CVSS 7.1 high Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtd_write pre-flash validation routine triggered by…
  • CVE-2026-76869 CVSS 8.6 high Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in reboot_timer_set.cgi caused by improper sscanf token parsing…
  • CVE-2026-76868 CVSS 6.9 medium Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in route_policy_add.cgi caused by a missing exit_port…
  • CVE-2026-76867 CVSS 5.1 medium Netcore NR255-V firmware version 1.5.130703 contains a stored cross-site scripting vulnerability in routing and NAT configuration CGI…
  • CVE-2026-76866 CVSS 8.6 high Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplied DDNS input in DDNSset_cgi.c and…
  • CVE-2026-76865 CVSS 6.9 medium Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in the QoS setter CGI handlers filter_conn_del_cgi.c…
  • CVE-2026-76864 CVSS 4.8 medium NR255-V version 1.5.130703 fails to sanitize QoS rule names before they are parsed via eval() in qos_xianz_add_cgi, qos_xianz_show_cgi…
  • CVE-2026-76863 CVSS 5.3 medium Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the mod_qos_bandwidth plan.json handling…
  • CVE-2026-76862 CVSS 8.7 high Netcore NR255-V version 1.5.130703 contains an os command argument injection vulnerability in the Nettools tcpdump launch paths, including…
  • CVE-2026-76861 CVSS 8.7 high Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in ntools_tcpdump_start_set.cgi caused by an unsized sprintf…
  • CVE-2026-76860 CVSS 8.7 high Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in wake_up_set.cgi caused by unbounded tokenization of MAC and…
  • CVE-2026-76859 CVSS 7.1 high Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the user_pass_show.cgi component…
  • CVE-2026-76858 CVSS 4.8 medium Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in ddns_wan_list_show.cgi caused by unsafe eval()…
  • CVE-2026-76857 CVSS 7.1 high Netcore NR255-V firmware version 1.5.130703 contains a sensitive information disclosure vulnerability in the ddns_wan_list_show.cgi…
  • CVE-2026-76856 CVSS 7.0 high Netcore NR255-V firmware version 1.5.130703 contains a cross-site request forgery vulnerability affecting the wan_config_set_cgi…
  • CVE-2026-76855 CVSS 7.1 high Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the audit endpoints handled by…
  • CVE-2026-76854 CVSS 7.1 high Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l7_web_auth_user_show.cgi related to…