vciy

CVEs we hold for Netcore

Records whose assigning authority named Netcore as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-92257Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting in L7 Content Management via eval() SinksNetcore NR255-V
CVE-2026-92256Netcore NR255-V 1.5.130703 IPsec PSK and RSA Key Disclosure via l2tpd_config_show.cgi Read HandlersNetcore NR255-V
CVE-2026-92255Netcore NR255-V 1.5.130703 Out-of-Bounds Read in filter_arp_put_file.cgi via String API MisuseNetcore NR255-V
CVE-2026-76873Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting via DHCP and ARP Hostname FieldsNetcore NR255-V
CVE-2026-76872Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting via DHCP/ACL Management PagesNetcore NR255-V
CVE-2026-76871Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via VPN Read HandlersNetcore NR255-V
CVE-2026-76870Netcore NR255-V 1.5.130703 Out-of-Bounds Read in mtd_write Firmware Upload ValidationNetcore NR255-V
CVE-2026-76869Netcore NR255-V 1.5.130703 Stack-Based Buffer Overflow in reboot_timer_set.cgiNetcore NR255-V
CVE-2026-76868Netcore NR255-V 1.5.130703 NULL Pointer Dereference in route_policy_add.cgi via Missing exit_portNetcore NR255-V
CVE-2026-76867Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting in Route/NAT Configuration CGI HandlersNetcore NR255-V
CVE-2026-76866Netcore NR255-V 1.5.130703 OS Command Argument Injection via Unquoted DDNS ParametersNetcore NR255-V
CVE-2026-76865Netcore NR255-V 1.5.130703 NULL Pointer Dereference via Unchecked atoi() in QoS Setter HandlersNetcore NR255-V
CVE-2026-76864Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting via Unescaped QoS Rule NamesNetcore NR255-V
CVE-2026-76863Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via QoS Bandwidth Plan RoutesNetcore NR255-V
CVE-2026-76862Netcore NR255-V 1.5.130703 OS Command Argument Injection in Nettools tcpdump Launch PathsNetcore NR255-V
CVE-2026-76861Netcore NR255-V 1.5.130703 Stack-Based Buffer Overflow in ntools_tcpdump_start_set.cgiNetcore NR255-V
CVE-2026-76860Netcore NR255-V 1.5.130703 Stack-Based Buffer Overflow in wake_up_set.cgi via MAC and ID TokenizationNetcore NR255-V
CVE-2026-76859Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via user_pass_show.cgiNetcore NR255-V
CVE-2026-76858Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting via DDNS eval() in ddns_wan_list_show.cgiNetcore NR255-V
CVE-2026-76857Netcore NR255-V 1.5.130703 Plaintext DDNS Credential Disclosure via ddns_wan_list_show.cgiNetcore NR255-V
CVE-2026-76856Netcore NR255-V 1.5.130703 Cross-Site Request Forgery in WAN/LAN Configuration EndpointsNetcore NR255-V
CVE-2026-76855Netcore NR255-V 1.5.130703 Cross-User Session Disclosure via Audit EndpointsNetcore NR255-V
CVE-2026-76854Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via l7_web_auth_user_show.cgiNetcore NR255-V
CVE-2026-76853Netcore NR268 1.7.121109 Security Check Bypass in parame_put_file.cgiNetcore NR268
CVE-2026-76852Netcore NR268 1.7.121109 Forgeable Firmware Authenticity Check in mtd_writeNetcore NR268
CVE-2026-4840Netcore Power 15AX Diagnostic Tool netis.cgi setTools os command injectionNetcore Power 15AX
CVE-2025-5147Netcore NBR1005GPEV2/NBR200V2/B6V2 network_tools tools_ping command injectionNetcore B6V2
CVE-2025-5146Netcore NBR200V2 HTTP Header routerd passwd_set command injectionNetcore NBR200V2
CVE-2025-5145Netcore POWER13 Query String cgi-bin command injectionNetcore POWER13
CVE-2025-34117Netcore / Netis Routers RCE via UDP Port 53413 BackdoorNetcore Technology Router firmware; Netis Router firmware

30 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.