CVE-2026-76856 HIGH

CVE-2026-76856: Netcore NR255-V 1.5.130703 Cross-Site Request Forgery in WAN/LAN Configuration Endpoints

Vendor Netcore
Product NR255-V
Weakness CWE-352 · CSRF
Published September 15, 2026
Last update September 15, 2026

CVSS base score

7.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction —
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Netcore NR255-V firmware version 1.5.130703 contains a cross-site request forgery vulnerability affecting the wan_config_set_cgi, wan_num_set_cgi, and lan_ip_change_cgi endpoints. Attackers can craft forged requests to trick authenticated administrators into modifying WAN or LAN network configuration settings without consent.

Key dates

02Disclosure timeline

September 15, 2026 CVE published

Related vulnerabilities

04Related CVE