CVE-2026-76856

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
8.1
HIGH

Description

Netcore NR255-V firmware version 1.5.130703 contains a cross-site request forgery vulnerability affecting the wan_config_set_cgi, wan_num_set_cgi, and lan_ip_change_cgi endpoints. Attackers can craft forged requests to trick authenticated administrators into modifying WAN or LAN network configuration settings without consent.

Published
September 15, 2026 10:16 PM
Last Modified
September 15, 2026 10:16 PM
Source
[email protected]

Weaknesses (CWE)

CWE-352

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.