Impact
Netcore NR255-V version 1.5.130703 contains an OS command argument injection flaw in several tcpdump launch paths such as ntools_start_set_cgi, ntools_tcpdump_start_set_cgi, exe_default, and ntools_proc. By injecting crafted arguments into these routines, an attacker can manipulate the system commands that the device executes, potentially allowing arbitrary command execution on the device.
Affected Systems
Netcore NR255-V routers running firmware version 1.5.130703 are affected. The vulnerable components include the Nettools tcpdump launch paths mentioned above.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity impact. With an EPSS score of less than 1%, the likelihood of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. However, the attack is inferred to be possible through the router’s web interface (CGI) components, which, if accessible to an attacker, could lead to remote command execution. The combination of high severity and low exploitation probability still warrants prompt attention.
OpenCVE Enrichment