CVE-2026-76856
Deferred Deferred - Pending Action

Cross-Site Request Forgery in Netcore NR255-V Firmware

Vulnerability report for CVE-2026-76856, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-21

Assigner: VulnCheck

Description

Netcore NR255-V firmware version 1.5.130703 contains a cross-site request forgery vulnerability affecting the wan_config_set_cgi, wan_num_set_cgi, and lan_ip_change_cgi endpoints. Attackers can craft forged requests to trick authenticated administrators into modifying WAN or LAN network configuration settings without consent.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-21
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
netcore nr255-v 1.5.130703

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cross-site request forgery (CSRF) issue in Netcore NR255-V firmware version 1.5.130703. It affects specific endpoints (wan_config_set_cgi, wan_num_set_cgi, lan_ip_change_cgi) and allows attackers to craft malicious requests that trick authenticated administrators into changing WAN or LAN network settings without their knowledge or consent.

Detection Guidance

Detecting this vulnerability requires monitoring network traffic for unauthorized POST requests to the vulnerable CGI endpoints (wan_config_set_cgi, wan_num_set_cgi, lan_ip_change_cgi). Inspect web server logs for unusual administrative actions or configuration changes. Use network monitoring tools like Wireshark to capture and analyze HTTP traffic targeting these endpoints.

Impact Analysis

An attacker could exploit this to alter your network configuration, potentially redirecting traffic, disrupting internet access, or exposing internal systems to unauthorized access. Since it requires an authenticated admin, phishing or social engineering might be needed to trick the admin into triggering the request.

Mitigation Strategies

Immediately update the Netcore NR255-V firmware to the latest version. Disable or restrict access to the vulnerable CGI endpoints via firewall rules. Implement CSRF tokens for administrative interfaces. Monitor network configurations for unauthorized changes and enforce multi-factor authentication for administrative access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76856. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart