Impact
Netcore NR255‑V firmware 1.5.130703 builds root‑run command lines from unquoted user‑supplied DDNS input in DDNSset_cgi.c and related ddns_Proc.c components, enabling attackers to inject arbitrary OS command arguments. This flaw is a classic OS command injection weakness, allowing malicious command payloads to execute with root privileges and potentially compromise the entire device.
Affected Systems
Affected systems are Netcore NR255‑V routers running firmware version 1.5.130703. The vulnerability does not appear to affect other firmware versions.
Risk and Exploitability
With a CVSS score of 8.6 and an EPSS score below 1 %, the likelihood of exploitation in the wild is low, yet the potential impact is high. Successful exploitation would give root‑level access, permitting an attacker to run arbitrary commands on the device. The vulnerability is not listed in CISA’s KEV catalog, and no public exploitation reports are known. It is inferred that attackers would need remote access to the DDNS configuration interface, typically through the router’s HTTP interface, and the device must be reachable on the local network segment; the attack vector is therefore most likely remote from a nearby device or trusted network.
OpenCVE Enrichment