HIGH 8.6 NVD
CVE-2026-76866
Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplied DDNS input in DDNSset_cgi.c and related ddns_Proc.c compon
Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplied DDNS input in DDNSset_cgi.c and related ddns_Proc.c components, enabling os command argument injection. Attackers can exploit the unsanitized parameters to inject additional command arguments executed with root privileges.
References
- https://github.com/draw-ctf/netcore-router-public-refs/blob/main/2026.08.19-netcore-nr255v
- https://www.vulncheck.com/advisories/netcore-nr255-v-1.5.130703-os-command-argument-inject
This high severity vulnerability with a CVSS score of 8.6 was published on 2026-09-15 via NVD.
vulnfeed aggregates 14340 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.