Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

NR255-V — Vulnerabilities & Security Advisories 23

All 23 CVE vulnerabilities found in NR255-V, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with Product NR255-V. The collection compiles known defects, including buffer overflows, authentication failures, and denial-of-service issues, covering advisories published from 2023 to 2024. Readers can track vendor advisories, understand specific weakness classes, and review the product’s vulnerability history. This resource serves as a central reference for identifying patterns in exposure and remediation status. No specific CVE IDs are listed; the focus is on the nature and timing of reported flaws.

Vendor: Netcore

CVE ID Title CVSS Severity Published
CVE-2026-92257 Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting in L7 Content Management via eval() Sinks CWE-79 5.4 Medium 2026-09-15
CVE-2026-92256 Netcore NR255-V 1.5.130703 IPsec PSK and RSA Key Disclosure via l2tpd_config_show.cgi Read Handlers CWE-522 6.5 Medium 2026-09-15
CVE-2026-92255 Netcore NR255-V 1.5.130703 Out-of-Bounds Read in filter_arp_put_file.cgi via String API Misuse CWE-125 5.4 Medium 2026-09-15
CVE-2026-76873 Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting via DHCP and ARP Hostname Fields CWE-79 5.2 Medium 2026-09-15
CVE-2026-76872 Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting via DHCP/ACL Management Pages CWE-79 5.4 Medium 2026-09-15
CVE-2026-76871 Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via VPN Read Handlers CWE-522 6.5 Medium 2026-09-15
CVE-2026-76870 Netcore NR255-V 1.5.130703 Out-of-Bounds Read in mtd_write Firmware Upload Validation CWE-125 7.1 High 2026-09-15
CVE-2026-76869 Netcore NR255-V 1.5.130703 Stack-Based Buffer Overflow in reboot_timer_set.cgi CWE-121 7.2 High 2026-09-15
CVE-2026-76868 Netcore NR255-V 1.5.130703 NULL Pointer Dereference in route_policy_add.cgi via Missing exit_port CWE-476 4.9 Medium 2026-09-15
CVE-2026-76867 Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting in Route/NAT Configuration CGI Handlers CWE-79 5.4 Medium 2026-09-15
CVE-2026-76866 Netcore NR255-V 1.5.130703 OS Command Argument Injection via Unquoted DDNS Parameters CWE-88 7.2 High 2026-09-15
CVE-2026-76865 Netcore NR255-V 1.5.130703 NULL Pointer Dereference via Unchecked atoi() in QoS Setter Handlers CWE-476 4.9 Medium 2026-09-15
CVE-2026-76864 Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting via Unescaped QoS Rule Names CWE-79 4.8 Medium 2026-09-15
CVE-2026-76862 Netcore NR255-V 1.5.130703 OS Command Argument Injection in Nettools tcpdump Launch Paths CWE-88 8.8 High 2026-09-15
CVE-2026-76863 Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via QoS Bandwidth Plan Routes CWE-863 4.3 Medium 2026-09-15
CVE-2026-76861 Netcore NR255-V 1.5.130703 Stack-Based Buffer Overflow in ntools_tcpdump_start_set.cgi CWE-121 8.8 High 2026-09-15
CVE-2026-76860 Netcore NR255-V 1.5.130703 Stack-Based Buffer Overflow in wake_up_set.cgi via MAC and ID Tokenization CWE-121 8.8 High 2026-09-15
CVE-2026-76859 Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via user_pass_show.cgi CWE-522 6.5 Medium 2026-09-15
CVE-2026-76858 Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting via DDNS eval() in ddns_wan_list_show.cgi CWE-79 4.8 Medium 2026-09-15
CVE-2026-76857 Netcore NR255-V 1.5.130703 Plaintext DDNS Credential Disclosure via ddns_wan_list_show.cgi CWE-522 6.5 Medium 2026-09-15
CVE-2026-76855 Netcore NR255-V 1.5.130703 Cross-User Session Disclosure via Audit Endpoints CWE-359 6.5 Medium 2026-09-15
CVE-2026-76856 Netcore NR255-V 1.5.130703 Cross-Site Request Forgery in WAN/LAN Configuration Endpoints CWE-352 8.1 High 2026-09-15
CVE-2026-76854 Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via l7_web_auth_user_show.cgi CWE-522 6.5 Medium 2026-09-15

All 23 known CVE vulnerabilities affecting NR255-V with full Chinese analysis, references, and POCs where available.