VulnSea

Netcore has 32 CVEs on record. Disclosure cadence is accelerating: 32 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 32. The median CVSS is 6.8 (medium), with 7 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-79 (6) and CWE-522 (5). Most affected products: NR255-V (23), NBR200V2 (7), NR268 (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.8
Publish → KEV
Last 90 days
32 prev 0

Products

  • NR255-V 23
  • NBR200V2 7
  • NR268 2
32
Total CVEs
7
Critical
0
CISA KEV
0
Exploited

Netcore vulnerabilities

CVEs affecting Netcore, newest first. Open any entry for full detail, references, and exploit status.

32 CVEsRSS

CVE-2026-94101Critical· 9.9PoC
today

A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246

A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argument wan_num leads to buffer overflow. It…

AbyssalNetcore · NBR200V2EPSS 0.45%via NVD
CVE-2026-94100Critical· 9.9
today

A weakness has been identified in Netcore NBR200V2 1.3.241127.071246

A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the component WAN VLAN Reconfiguration. Executing a manipulation of the argument vlan_wanX…

MidnightNetcore · NBR200V2EPSS 0.46%via NVD
CVE-2026-94099Critical· 9.9
today

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results…

MidnightNetcore · NBR200V2EPSS 1.7%via NVD
CVE-2026-94098Critical· 9.1PoC
today

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING…

AbyssalNetcore · NBR200V2EPSS 2.4%via NVD
CVE-2026-94097Critical· 10.0
today

A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246

A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes co…

MidnightNetcore · NBR200V2EPSS 2.0%via NVD
CVE-2026-94096Critical· 9.9PoC
today

A vulnerability was found in Netcore NBR200V2 1.3.241127.071246

A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4…

AbyssalNetcore · NBR200V2EPSS 1.7%via NVD
CVE-2026-94095Critical· 9.9
today

A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246

A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the a…

MidnightNetcore · NBR200V2EPSS 1.7%via NVD
CVE-2026-92257Medium· 5.4
6d ago

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages that use eval() sinks, affecting the call board text and policy group handling components

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages that use eval() sinks, affecting the call board text and policy group handling components. Attackers can inject persis…

SunlitNetcore · NR255-VEPSS 0.18%via NVD
CVE-2026-92256Medium· 6.5
6d ago

NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l2tpd_config_show_cgi.c, ipsec_show_cgi.c, and mod_vpn_remote/plan.json read handlers

NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l2tpd_config_show_cgi.c, ipsec_show_cgi.c, and mod_vpn_remote/plan.json read handlers. Attackers can query l2tpd_config_show.cgi to expose stored IPs…

SunlitNetcore · NR255-VEPSS 0.28%via NVD
CVE-2026-92255Medium· 5.4
6d ago

Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by improper use of a string handling API

Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by improper use of a string handling API. Attackers can trigger an unterminated buffer over-read by exploiting this flaw in…

SunlitNetcore · NR255-VEPSS 0.27%via NVD
CVE-2026-76873Medium· 5.2
6d ago

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in the DHCP dynamic IP display and ARP bind list display components handling hostname fields

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in the DHCP dynamic IP display and ARP bind list display components handling hostname fields. A LAN-based attacker can inject malicious script throug…

SunlitNetcore · NR255-VEPSS 0.19%via NVD
CVE-2026-76872Medium· 5.4
6d ago

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in DHCP static IP and IP ACL management pages, including dhcp_add_staticip_cgi, dhcp_staticip_show_cgi, ip_acl_set_cgi, and ip_acl_show_cgi

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in DHCP static IP and IP ACL management pages, including dhcp_add_staticip_cgi, dhcp_staticip_show_cgi, ip_acl_set_cgi, and ip_acl_show_cgi. Attacker…

SunlitNetcore · NR255-VEPSS 0.18%via NVD
CVE-2026-76871Medium· 6.5
6d ago

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in mod_vpn_remote/plan.json, pptpd_user_show.cgi, pptp_client_config_show.cgi, and l2tpd_user_show.cgi

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in mod_vpn_remote/plan.json, pptpd_user_show.cgi, pptp_client_config_show.cgi, and l2tpd_user_show.cgi. Attackers can leverage these components …

SunlitNetcore · NR255-VEPSS 0.28%via NVD
CVE-2026-76870High· 7.1
6d ago

Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtd_write pre-flash validation routine triggered by short firmware uploads

Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtd_write pre-flash validation routine triggered by short firmware uploads. Attackers can upload a truncated firmware image via put_file_cgi.c to trig…

TwilightNetcore · NR255-VEPSS 0.31%via NVD
CVE-2026-76869High· 7.2
6d ago

Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in reboot_timer_set.cgi caused by improper sscanf token parsing

Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in reboot_timer_set.cgi caused by improper sscanf token parsing. Attackers can exploit this flaw by submitting crafted input to the affected endpoint to corrupt st…

TwilightNetcore · NR255-VEPSS 0.43%via NVD
CVE-2026-76868Medium· 4.9
6d ago

Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in route_policy_add.cgi caused by a missing exit_port parameter

Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in route_policy_add.cgi caused by a missing exit_port parameter. Attackers can send requests lacking the exit_port field to trigger the null pointer der…

SunlitNetcore · NR255-VEPSS 0.36%via NVD
CVE-2026-76867Medium· 5.4
6d ago

Netcore NR255-V firmware version 1.5.130703 contains a stored cross-site scripting vulnerability in routing and NAT configuration CGI components including routing_tab_add_cgi, routing_table_list_show_cgi, route_policy_add_cgi, and route_…

Netcore NR255-V firmware version 1.5.130703 contains a stored cross-site scripting vulnerability in routing and NAT configuration CGI components including routing_tab_add_cgi, routing_table_list_show_cgi, route_policy_add_cgi, and route_…

SunlitNetcore · NR255-VEPSS 0.18%via NVD
CVE-2026-76866High· 7.2
6d ago

Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplied DDNS input in DDNSset_cgi.c and related ddns_Proc.c components, enabling os command argument injection

Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplied DDNS input in DDNSset_cgi.c and related ddns_Proc.c components, enabling os command argument injection. Attackers can exploit the unsan…

TwilightNetcore · NR255-VEPSS 0.43%via NVD
CVE-2026-76865Medium· 4.9
6d ago

Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in the QoS setter CGI handlers filter_conn_del_cgi.c and gre_prio_set_cgi.c due to unchecked atoi() results

Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in the QoS setter CGI handlers filter_conn_del_cgi.c and gre_prio_set_cgi.c due to unchecked atoi() results. An attacker can trigger the flaw by supplyi…

SunlitNetcore · NR255-VEPSS 0.36%via NVD
CVE-2026-76864Medium· 4.8
6d ago

NR255-V version 1.5.130703 fails to sanitize QoS rule names before they are parsed via eval() in qos_xianz_add_cgi, qos_xianz_show_cgi, qos_filter_add_cgi, and qos_filter_show_cgi handlers

NR255-V version 1.5.130703 fails to sanitize QoS rule names before they are parsed via eval() in qos_xianz_add_cgi, qos_xianz_show_cgi, qos_filter_add_cgi, and qos_filter_show_cgi handlers. An attacker can inject persistent script code t…

SunlitNetcore · NR255-VEPSS 0.19%via NVD
CVE-2026-76863Medium· 4.3
6d ago

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the mod_qos_bandwidth plan.json handling within filter_conns_dump_cgi.c and IGD_CgiCall.c

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the mod_qos_bandwidth plan.json handling within filter_conns_dump_cgi.c and IGD_CgiCall.c. Authenticated users with broad roles can access th…

SunlitNetcore · NR255-VEPSS 0.22%via NVD
CVE-2026-76862High· 8.8
6d ago

Netcore NR255-V version 1.5.130703 contains an os command argument injection vulnerability in the Nettools tcpdump launch paths, including ntools_start_set_cgi, ntools_tcpdump_start_set_cgi, exe_default, and ntools_proc components

Netcore NR255-V version 1.5.130703 contains an os command argument injection vulnerability in the Nettools tcpdump launch paths, including ntools_start_set_cgi, ntools_tcpdump_start_set_cgi, exe_default, and ntools_proc components. Attac…

TwilightNetcore · NR255-VEPSS 0.41%via NVD
CVE-2026-76861High· 8.8
6d ago

Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in ntools_tcpdump_start_set.cgi caused by an unsized sprintf call when processing form values

Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in ntools_tcpdump_start_set.cgi caused by an unsized sprintf call when processing form values. An attacker can submit crafted input to this cgi endpoint to overflo…

TwilightNetcore · NR255-VEPSS 0.51%via NVD
CVE-2026-76860High· 8.8
6d ago

Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in wake_up_set.cgi caused by unbounded tokenization of MAC and ID input

Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in wake_up_set.cgi caused by unbounded tokenization of MAC and ID input. Attackers can supply crafted MAC and ID values to the affected endpoint to overflow the st…

TwilightNetcore · NR255-VEPSS 0.41%via NVD
CVE-2026-76859Medium· 6.5
6d ago

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the user_pass_show.cgi component

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the user_pass_show.cgi component. Low-privilege attackers can exploit this flaw via ui_config_2.xml and misc.js to disclose router credentials.

SunlitNetcore · NR255-VEPSS 0.34%via NVD
CVE-2026-76858Medium· 4.8
6d ago

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in ddns_wan_list_show.cgi caused by unsafe eval() handling of DDNS data

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in ddns_wan_list_show.cgi caused by unsafe eval() handling of DDNS data. Attackers can inject malicious script through the DDNS configuration path, l…

SunlitNetcore · NR255-VEPSS 0.28%via NVD
CVE-2026-76857Medium· 6.5
6d ago

Netcore NR255-V firmware version 1.5.130703 contains a sensitive information disclosure vulnerability in the ddns_wan_list_show.cgi endpoint and related DDNSset_cgi, IGD_GetCgiHandler, and IGD_CgiCall components

Netcore NR255-V firmware version 1.5.130703 contains a sensitive information disclosure vulnerability in the ddns_wan_list_show.cgi endpoint and related DDNSset_cgi, IGD_GetCgiHandler, and IGD_CgiCall components. Attackers who reach this…

SunlitNetcore · NR255-VEPSS 0.34%via NVD
CVE-2026-76856High· 8.1
6d ago

Netcore NR255-V firmware version 1.5.130703 contains a cross-site request forgery vulnerability affecting the wan_config_set_cgi, wan_num_set_cgi, and lan_ip_change_cgi endpoints

Netcore NR255-V firmware version 1.5.130703 contains a cross-site request forgery vulnerability affecting the wan_config_set_cgi, wan_num_set_cgi, and lan_ip_change_cgi endpoints. Attackers can craft forged requests to trick authenticate…

TwilightNetcore · NR255-VEPSS 0.16%via NVD
CVE-2026-76855Medium· 6.5
6d ago

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the audit endpoints handled by l7_web_auth_log_dump_cgi.c, audit_get_cgi.c, and mod_dispatch_auth/plan.json

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the audit endpoints handled by l7_web_auth_log_dump_cgi.c, audit_get_cgi.c, and mod_dispatch_auth/plan.json. Attackers can query these audit …

SunlitNetcore · NR255-VEPSS 0.38%via NVD
CVE-2026-76854Medium· 6.5
6d ago

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l7_web_auth_user_show.cgi related to captive-portal credential handling

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l7_web_auth_user_show.cgi related to captive-portal credential handling. Attackers can query this component to obtain captive-portal user cre…

SunlitNetcore · NR255-VEPSS 0.46%via NVD
Netcore vulnerabilities (CVEs) · VulnSea