Impact
The router firmware fails to sanitize QoS rule names before they are parsed by eval in several CGI handlers. A crafted rule name containing script code can be stored persistently and later executed when the data is processed. This results in a stored cross‑site scripting vulnerability that exploits a data‑validation weakness identified as CWE‑79. The impact is client web interface; the advisory does not detail specific downstream effects.
Affected Systems
Netcore NR255‑V devices running firmware version 1.5.130703 are affected. Users who add or view QoS rules with unsanitized names risk exposure.
Risk and Exploitability
The CVSS score is 4.8, the EPSS score is less it is not listed in the CISA KEV catalog. Based on the description, it can be inferred that authenticating to the router’s management interface and creating or modifying QoS rules would be necessary to inject malicious payloads, making this a stored XSS scenario. The advisory does not elaborate on concrete exploitation outcomes beyond this behavior.
OpenCVE Enrichment