CVE-2026-76856: Netcore NR255-V 1.5.130703 Cross-Site Request Forgery in WAN/LAN Configuration Endpoints
Netcore NR255-V firmware version 1.5.130703 contains a cross-site request forgery vulnerability affecting the wanconfigsetcgi, wannumsetcgi, and lanipchangecgi endpoints. Attackers can craft forged requests to trick authenticated administrators into modifying WAN or LAN network configuration settings without consent.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker must be able to get an authenticated administrator to interact with a forged request. No attacker authentication is required, but exploitation requires user interaction.
Which configuration functions can be changed through the vulnerable endpoints?
The affected endpoints handle WAN configuration, WAN interface or connection count settings, and LAN IP changes. A successful forged request can cause an administrator's router to apply network configuration changes without their consent.
How can I determine whether my device is affected?
Confirm whether the device is a Netcore NR255-V running firmware version 1.5.130703. The reported vulnerable endpoints are wan_config_set_cgi, wan_num_set_cgi, and lan_ip_change_cgi.