Impact
The vulnerability is a stored cross‑site scripting flaw (CWE‑79) found in the routing and NAT configuration CGI handlers of Netcore NR255‑V routers. Attackers can inject persistent script payloads into pages such as routing_tab_add_cgi and route_policy_add_cgi. When a user or administrator subsequently accesses those pages, the stored scripts execute in the browser context, potentially enabling session hijacking, data exfiltration, or defacement.
Affected Systems
Affected devices are Netcore NR255‑V routers running firmware version 1.5.130703. No other versions are enumer specific build is confirmed to contain the flaw. Update information is not provided, so administrators should review Netcore firmware releases for a patch.
Risk and Exploitability
The CVSS score of 5.1 and an EPSS of less than 1 % indicate a moderate overall risk, with a low probability of widespread exploitation at the present time. Based on the description, it is inferred that the vulnerability requires authenticated access to the router’s web interface in order to inject the malicious script, after which other users or administrators who view the amended configuration pages will be affected. The flaw is not listed in the CISA KEV catalog, so there are no known target exploits yet. Mitigating the risk relies on patching or disabling the vulnerable configuration paths.
OpenCVE Enrichment