Vulnerabilidades em Netcore
36 resultadosAnálise Vexday
Netcore possui 4 vulnerabilidades cadastradas, nenhuma com evidência de ataque ativo ou classificação crítica, e nenhuma publicada recentemente. A fraqueza dominante identificada é CWE-77 (Improper Neutralization of Special Elements used in a Command), indicando risco de injeção de comando que requer atenção em ciclos regulares de correção, mas sem pressão imediata de exploit.
CVE-2026-4840HIGHNetcore Power 15AX Diagnostic Tool netis.cgi setTools os command injectionEPSS 10.5%CVE-2025-5145MEDIUMNetcore POWER13 Query String cgi-bin command injectionEPSS 1.1%CVE-2025-5147MEDIUMNetcore NBR1005GPEV2/NBR200V2/B6V2 network_tools tools_ping command injectionEPSS 1.1%CVE-2025-5146MEDIUMNetcore NBR200V2 HTTP Header routerd passwd_set command injectionEPSS 1.1%CVE-2026-76861HIGHNetcore NR255-V 1.5.130703 Stack-Based Buffer Overflow in ntools_tcpdump_start_set.cgiEPSS 0.5%CVE-2026-76854HIGHNetcore NR255-V 1.5.130703 Sensitive Information Disclosure via l7_web_auth_user_show.cgiEPSS 0.5%CVE-2026-76869HIGHNetcore NR255-V 1.5.130703 Stack-Based Buffer Overflow in reboot_timer_set.cgiEPSS 0.4%CVE-2026-76866HIGHNetcore NR255-V 1.5.130703 OS Command Argument Injection via Unquoted DDNS ParametersEPSS 0.4%CVE-2026-76860HIGHNetcore NR255-V 1.5.130703 Stack-Based Buffer Overflow in wake_up_set.cgi via MAC and ID TokenizationEPSS 0.4%CVE-2026-76862HIGHNetcore NR255-V 1.5.130703 OS Command Argument Injection in Nettools tcpdump Launch PathsEPSS 0.4%CVE-2026-76855HIGHNetcore NR255-V 1.5.130703 Cross-User Session Disclosure via Audit EndpointsEPSS 0.4%CVE-2026-76865MEDIUMNetcore NR255-V 1.5.130703 NULL Pointer Dereference via Unchecked atoi() in QoS Setter HandlersEPSS 0.4%CVE-2026-76868MEDIUMNetcore NR255-V 1.5.130703 NULL Pointer Dereference in route_policy_add.cgi via Missing exit_portEPSS 0.4%CVE-2026-76859HIGHNetcore NR255-V 1.5.130703 Sensitive Information Disclosure via user_pass_show.cgiEPSS 0.3%CVE-2026-76857HIGHNetcore NR255-V 1.5.130703 Plaintext DDNS Credential Disclosure via ddns_wan_list_show.cgiEPSS 0.3%CVE-2026-76870HIGHNetcore NR255-V 1.5.130703 Out-of-Bounds Read in mtd_write Firmware Upload ValidationEPSS 0.3%CVE-2026-76858MEDIUMNetcore NR255-V 1.5.130703 Stored Cross-Site Scripting via DDNS eval() in ddns_wan_list_show.cgiEPSS 0.3%CVE-2026-76871HIGHNetcore NR255-V 1.5.130703 Sensitive Information Disclosure via VPN Read HandlersEPSS 0.3%CVE-2026-92256HIGHNetcore NR255-V 1.5.130703 IPsec PSK and RSA Key Disclosure via l2tpd_config_show.cgi Read HandlersEPSS 0.3%CVE-2026-92255MEDIUMNetcore NR255-V 1.5.130703 Out-of-Bounds Read in filter_arp_put_file.cgi via String API MisuseEPSS 0.3%