Netcore Nr255-V vulnerabilities
23 known vulnerabilities affecting netcore/nr255-v.
Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM16
Vulnerabilities
Page 2 of 2
CVE-2026-76868P4MEDIUMCVSS 4.9v1.5.1307032026-09-15
CVE-2026-76868 [MEDIUM] CWE-476 CVE-2026-76868: Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in route_policy
Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in route_policy_add.cgi caused by a missing exit_port parameter. Attackers can send requests lacking the exit_port field to trigger the null pointer dereference, resulting in a denial of service.
nvd
CVE-2026-76858P4MEDIUMCVSS 4.8v1.5.1307032026-09-15
CVE-2026-76858 [MEDIUM] CWE-79 CVE-2026-76858: Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in ddns_wan_
Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in ddns_wan_list_show.cgi caused by unsafe eval() handling of DDNS data. Attackers can inject malicious script through the DDNS configuration path, leading to persistent execution when the affected page is viewed.
nvd
CVE-2026-76863P4MEDIUMCVSS 4.3v1.5.1307032026-09-15
CVE-2026-76863 [MEDIUM] CWE-863 CVE-2026-76863: Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the
Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the mod_qos_bandwidth plan.json handling within filter_conns_dump_cgi.c and IGD_CgiCall.c. Authenticated users with broad roles can access these QoS read routes to obtain live network telemetry beyond their intended privilege level.
nvd
← Previous2 / 2