Junglewise Threat Intelligence

CVE-2026-76866: Netcore NR255-V OS command argument injection in DDNS

CVE-2026-76866 · Severity: high · CVSS 7.2 · Published 2026-09-15

Technologies: Netcore NR255-V. Vendors: Netcore.

Executive brief

The Netcore NR255-V is a wireless router whose firmware includes a DDNS (Dynamic DNS) configuration feature. The feature contains a vulnerability where user-supplied input is not properly sanitized before being used to build system commands executed with root privileges. An authenticated attacker can inject additional command arguments through the DDNS parameters, potentially gaining complete control over the router.

Technical details

This vulnerability is an OS command argument injection (CWE-88) in the DDNS management component of Netcore NR255-V firmware version 1.5.130703. The vulnerable code is located in DDNSset_cgi.c and ddns_Proc.c, where unquoted user-supplied DDNS input is directly concatenated into command lines executed by the system with root privileges. The attack vector requires network access and administrative authentication to the router's web interface. By injecting shell metacharacters and argument delimiters into DDNS parameters, an attacker can break out of the intended command context and execute arbitrary commands with root privileges. No public patch information is currently available.

Affected products

  • Netcore NR255-V 1.5.130703

Timeline

  • 2026-09-04: disclosed
  • 2026-09-15: advisory: NVD published CVE-2026-76866

References

Related threats