Vendor
Netcore vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 32 vulnerabilities in Netcore: 7 in the last 7 days and 32 in the last 90 days, 7 of them critical and 0 exploited in the wild. The most recent, CVE-2026-94101, was published on 21 September 2026. 1 technology has a page of its own.
- Last 7 days
- 7
- Last 90 days
- 32
- Critical, all time
- 7
- Exploited in the wild
- 0
Netcore technologies
Latest Netcore vulnerabilities
- CVE-2026-94101: Netcore NBR200V2 buffer overflow in routerd VLAN handlercriticalCVSS 9.9EPSS 0.8%
- CVE-2026-94100: Netcore NBR200V2 buffer overflow in WAN VLAN configurationcriticalCVSS 9.9EPSS 0.8%
- CVE-2026-94099: Netcore NBR200V2 command injection in restore.cgicriticalCVSS 9.9EPSS 1.7%
- CVE-2026-94098: Netcore NBR200V2 command injection in firmware upgrade endpointcriticalCVSS 9.1EPSS 2.4%
- CVE-2026-94097: Netcore NBR200V2 command injection in network tools CGIcriticalCVSS 10EPSS 2.9%
- CVE-2026-94096: Netcore NBR200V2 command injection in LAN IP ConfigurationcriticalCVSS 9.9EPSS 2.0%
- CVE-2026-94095: Netcore NBR200V2 command injection in traceroute diagnosticcriticalCVSS 9.9EPSS 2.4%
- CVE-2026-92257: Netcore NR255-V stored cross-site scripting in L7 content managementmediumCVSS 5.4EPSS 0.2%
- CVE-2026-92256: Netcore NR255-V sensitive information disclosure in VPN configuration handlersmediumCVSS 6.5EPSS 0.4%
- CVE-2026-92255: Netcore NR255-V out-of-bounds read in filter_arp_put_file.cgimediumCVSS 5.4EPSS 0.4%
- CVE-2026-76873: Netcore NR255-V stored cross-site scripting in DHCP and ARP hostname fieldsmediumCVSS 5.2EPSS 0.2%
- CVE-2026-76872: Netcore NR255-V stored cross-site scripting in DHCP and ACL managementmediumCVSS 5.4EPSS 0.2%
- CVE-2026-76871: Netcore NR255-V credential disclosure in VPN componentsmediumCVSS 6.5EPSS 0.4%
- CVE-2026-76870: Netcore NR255-V out-of-bounds read in firmware upload validationhighCVSS 7.1EPSS 0.4%
- CVE-2026-76869: Netcore NR255-V stack-based buffer overflow in reboot_timer_set.cgihighCVSS 7.2EPSS 0.6%
- CVE-2026-76868: Netcore NR255-V null pointer dereference in route_policy_add.cgimediumCVSS 4.9EPSS 0.5%
- CVE-2026-76867: Netcore NR255-V stored XSS in routing and NAT configurationmediumCVSS 5.4EPSS 0.2%
- CVE-2026-76866: Netcore NR255-V OS command argument injection in DDNShighCVSS 7.2EPSS 0.6%
- CVE-2026-76865: Netcore NR255-V null pointer dereference in QoS handlersmediumCVSS 4.9EPSS 0.5%
- CVE-2026-76864: Netcore NR255-V stored XSS in QoS rule handlersmediumCVSS 4.8EPSS 0.3%
- CVE-2026-76863: Netcore NR255-V privilege escalation in QoS bandwidth routesmediumCVSS 4.3EPSS 0.3%
- CVE-2026-76862: Netcore NR255-V OS command argument injection in tcpdumphighCVSS 8.8EPSS 0.5%
- CVE-2026-76861: Netcore NR255-V stack buffer overflow in ntools_tcpdump_start_set.cgihighCVSS 8.8EPSS 0.7%
- CVE-2026-76860: Netcore NR255-V stack-based buffer overflow in wake_up_set.cgihighCVSS 8.8EPSS 0.5%
- CVE-2026-76859: Netcore NR255-V sensitive information disclosure in user_pass_show.cgimediumCVSS 6.5EPSS 0.4%
Most severe Netcore vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-94097: Netcore NBR200V2 command injection in network tools CGIcriticalCVSS 10EPSS 2.9%
- CVE-2026-94095: Netcore NBR200V2 command injection in traceroute diagnosticcriticalCVSS 9.9EPSS 2.4%
- CVE-2026-94096: Netcore NBR200V2 command injection in LAN IP ConfigurationcriticalCVSS 9.9EPSS 2.0%
- CVE-2026-94099: Netcore NBR200V2 command injection in restore.cgicriticalCVSS 9.9EPSS 1.7%
- CVE-2026-94101: Netcore NBR200V2 buffer overflow in routerd VLAN handlercriticalCVSS 9.9EPSS 0.8%
- CVE-2026-94100: Netcore NBR200V2 buffer overflow in WAN VLAN configurationcriticalCVSS 9.9EPSS 0.8%
- CVE-2026-94098: Netcore NBR200V2 command injection in firmware upgrade endpointcriticalCVSS 9.1EPSS 2.4%
- CVE-2026-76861: Netcore NR255-V stack buffer overflow in ntools_tcpdump_start_set.cgihighCVSS 8.8EPSS 0.7%
- CVE-2026-76862: Netcore NR255-V OS command argument injection in tcpdumphighCVSS 8.8EPSS 0.5%
- CVE-2026-76860: Netcore NR255-V stack-based buffer overflow in wake_up_set.cgihighCVSS 8.8EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 25 | 0 | |
| 21 Sep 2026 | 7 | 7 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/netcore.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Netcore vulnerabilities", https://junglewise.ai/threats/vendors/netcore, 26 September 2026.