CVE-2026-76862
Received Received - Intake

Netcore NR255-V TCPdump Command Injection Vulnerability

Vulnerability report for CVE-2026-76862, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: VulnCheck

Description

Netcore NR255-V version 1.5.130703 contains an os command argument injection vulnerability in the Nettools tcpdump launch paths, including ntools_start_set_cgi, ntools_tcpdump_start_set_cgi, exe_default, and ntools_proc components. Attackers can inject crafted arguments into these tcpdump launch routines to manipulate executed system commands on the device.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
netcore nr255-v 1.5.130703

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-88 The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an OS command argument injection flaw in Netcore NR255-V version 1.5.130703. Attackers can inject malicious arguments into tcpdump launch routines like ntools_start_set_cgi and ntools_tcpdump_start_set_cgi to manipulate system commands executed on the device.

Impact Analysis

An attacker could gain unauthorized control over the device by executing arbitrary commands. This may lead to data theft, system compromise, or disruption of services running on the affected device.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating confidentiality requirements in GDPR and HIPAA. Organizations may face legal penalties, reputational damage, and loss of compliance certifications.

Mitigation Strategies

Immediately update the Netcore NR255-V device to the latest firmware version that patches the tcpdump command injection vulnerability. Disable or restrict access to the vulnerable web interfaces (ntools_start_set_cgi, ntools_tcpdump_start_set_cgi) if updates are not immediately available. Monitor network traffic for unusual tcpdump command executions or unexpected system command invocations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76862. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart