Impact
A cross‑site request forgery flaw allows a malicious actor to forge HTTP requests that are processed by the netcore router’s web interface, causing authenticated administrators to inadvertently change WAN or LAN settings. The vulnerability is a classic CSRF, mapped to CWE‑352, and can lead to loss of connectivity, traffic interception, or diversion of data paths. No exploitation of user credentials or local system code is required – the flaw relies solely on the presence of an authenticated admin session.
Affected Systems
The flaw affects Netcore NR255‑V routers running firmware version 1.5.130703. The vulnerable endpoints are wan_config_set_cgi, wan_num_set_cgi, and lan_ip_change_cgi, which are used for WAN and LAN configuration changes.
Risk and Exploitability
The CVSS score of 7.0 indicates moderate severity. EPSS is less than 1 %, making widespread exploitation unlikely, and the issue is not listed in CISA’s KEV catalog. The most probable attack path requires the attacker to be able to convince an administrator to click a crafted link or submit a forged form while the admin is authenticated. In environments where router administration is publicly exposed or access control is weak, the risk rises, but without such exposure the likelihood of successful exploitation remains low.
OpenCVE Enrichment