Impact
Netcore NR255-V firmware version 1.5.130703 contains a stored cross‑site scripting vulnerability within ddns_wan_list_show.cgi. The flaw arises from an unsafe eval() call that processes DDNS data, allowing an attacker to inject malicious JavaScript through the DDNS configuration path. Once injected, the payload is stored and will execute each time an affected user opens the page, enabling persistent script execution and potential compromise of the web interface.
Affected Systems
The vulnerability affects Netcore NR255-V routers running firmware 1.5.130703. No other vendor or product versions are listed in the CNA data or the provided references.
Risk and Exploitability
The CVSS score of 4.8 reflects a moderate risk, and the EPSS score of <1% indicates a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to manipulate the DDNS configuration to embed the malicious script, which requires access to the router’s administrative interface. The stored nature of the flaw means the malicious code persists across reboots and affects all users who view the page, exposing them to potential session hijacking, credential theft, or other client‑side attacks.
OpenCVE Enrichment