Executive brief
The Netcore NR255-V is a wireless router used to provide internet connectivity in home and small office networks. This vulnerability allows an attacker to trick a logged-in administrator into unknowingly changing critical network settings (WAN or LAN configuration) by visiting a malicious webpage. An attacker could disrupt internet service, redirect traffic, or isolate the network from legitimate access.
Technical details
The Netcore NR255-V firmware 1.5.130703 contains a cross-site request forgery (CSRF) vulnerability in the wan_config_set_cgi, wan_num_set_cgi, and lan_ip_change_cgi endpoints. These endpoints lack proper CSRF protection (such as anti-CSRF tokens), allowing attackers to craft forged HTTP requests that execute with the privileges of an authenticated administrator. The attack requires that an administrator be logged into the router's web interface and be tricked into visiting a malicious webpage controlled by the attacker. A successful exploit enables unauthorized modification of WAN and LAN configuration settings, potentially disrupting network connectivity or redirecting traffic. Netcore has not released a patch as of the advisory date.
Affected products
- Netcore NR255-V 1.5.130703
Timeline
- 2026-09-15: disclosed: CVE-2026-76856 published on NVD
- 2026-09-04: other: Public reference published on GitHub by researchers Zhou Ao, Yin Luxing, Jiang Yuxuan, Liu Xin, @Nebusec