Junglewise Threat Intelligence

CVE-2026-76863: Netcore NR255-V privilege escalation in QoS bandwidth routes

CVE-2026-76863 · Severity: medium · CVSS 4.3 · Published 2026-09-15

Technologies: Netcore NR255-V. Vendors: Netcore.

Executive brief

The Netcore NR255-V is a home/small office router that manages network quality-of-service (QoS) settings to prioritize traffic. Authenticated users with limited roles can bypass access controls to view real-time network traffic data (telemetry) they should not have permission to see, potentially exposing network usage patterns and device activity to unauthorized accounts.

Technical details

This is a privilege escalation and authorization bypass vulnerability (CWE-863) in the mod_qos_bandwidth component, specifically in plan.json handling within filter_conns_dump_cgi.c and IGD_CgiCall.c. Authenticated users with broad roles can access QoS read routes that should be restricted by permission level, allowing them to retrieve live network telemetry beyond their intended access scope. The vulnerability requires prior authentication to exploit; network accessibility is not a constraint since it runs on the router management interface. An attacker with a low-privilege authenticated account can retrieve network monitoring data. CVSS v4.0 score is 5.3 (vector: AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N). Patch status is not documented in available references.

Affected products

  • Netcore NR255-V 1.5.130703

Timeline

  • 2026-09-04: disclosed
  • 2026-09-15: advisory

References

Related threats