Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplied DDNS input in DDNSset_cgi.c and related ddns_Proc.c components, enabling os command argument injection. Attackers can exploit the unsanitized parameters to inject additional command arguments executed with root privileges. | |
| Title | Netcore NR255-V 1.5.130703 OS Command Argument Injection via Unquoted DDNS Parameters | |
| Weaknesses | CWE-88 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T21:57:58.285Z
Reserved: 2026-08-19T21:47:08.936Z
Link: CVE-2026-76866
No data.
Status : Received
Published: 2026-09-15T22:17:01.337
Modified: 2026-09-15T22:17:01.337
Link: CVE-2026-76866
No data.
OpenCVE Enrichment
No data.
