Junglewise Threat Intelligence

CVE-2026-76862: Netcore NR255-V OS command argument injection in tcpdump

CVE-2026-76862 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Netcore NR255-V. Vendors: Netcore.

Executive brief

The Netcore NR255-V is a residential router that includes network diagnostic tools. A vulnerability in the tcpdump network packet capture functionality allows authenticated attackers to inject arbitrary command-line arguments, potentially leading to remote code execution on the device. This could enable attackers to compromise the router, intercept network traffic, or use it as a pivot point into the customer's home network.

Technical details

The vulnerability is an OS command argument injection (CWE-88) in the tcpdump launch paths across multiple components: ntools_start_set_cgi, ntools_tcpdump_start_set_cgi, exe_default, and ntools_proc. The affected version 1.5.130703 fails to properly sanitize user-supplied input before passing it as arguments to the tcpdump system command. An authenticated attacker can craft malicious arguments to manipulate the executed system command, achieving remote code execution on the device. The attack requires network access and valid authentication credentials; no patch status is currently disclosed.

Affected products

  • Netcore NR255-V 1.5.130703

Timeline

  • 2026-09-04: disclosed
  • 2026-09-15: advisory

References

Related threats