Description
Netcore NR255-V firmware version 1.5.130703 contains a stored cross-site scripting vulnerability in routing and NAT configuration CGI components including routing_tab_add_cgi, routing_table_list_show_cgi, route_policy_add_cgi, and route_policy_parame_show_cgi. Attackers can inject persistent script payloads through these route and NAT configuration pages, which are then executed in the context of users viewing the affected pages.
Published: 2026-09-15
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Firmware
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw (CWE‑79) found in the routing and NAT configuration CGI handlers of Netcore NR255‑V routers. Attackers can inject persistent script payloads into pages such as routing_tab_add_cgi and route_policy_add_cgi. When a user or administrator subsequently accesses those pages, the stored scripts execute in the browser context, potentially enabling session hijacking, data exfiltration, or defacement.

Affected Systems

Affected devices are Netcore NR255‑V routers running firmware version 1.5.130703. No other versions are enumer specific build is confirmed to contain the flaw. Update information is not provided, so administrators should review Netcore firmware releases for a patch.

Risk and Exploitability

The CVSS score of 5.1 and an EPSS of less than 1 % indicate a moderate overall risk, with a low probability of widespread exploitation at the present time. Based on the description, it is inferred that the vulnerability requires authenticated access to the router’s web interface in order to inject the malicious script, after which other users or administrators who view the amended configuration pages will be affected. The flaw is not listed in the CISA KEV catalog, so there are no known target exploits yet. Mitigating the risk relies on patching or disabling the vulnerable configuration paths.

Generated by OpenCVE AI on September 16, 2026 at 21:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router firmware to a version that removes the stored XSS vulnerability in the route and NAT configuration CGI handlers.
  • If an upgrade is not immediately possible, restrict access to the router’s web interface to trusted internal networks, enforce strong authentication, and implement network segmentation to limit exposure.
  • As a temporary measure, apply input sanitization or output encoding to the affected CGI pages so that any injected script is escaped before rendering.

Generated by OpenCVE AI on September 16, 2026 at 21:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Netcore NR255-V firmware version 1.5.130703 contains a stored cross-site scripting vulnerability in routing and NAT configuration CGI components including routing_tab_add_cgi, routing_table_list_show_cgi, route_policy_add_cgi, and route_policy_parame_show_cgi. Attackers can inject persistent script payloads through these route and NAT configuration pages, which are then executed in the context of users viewing the affected pages.
Title Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting in Route/NAT Configuration CGI Handlers
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T21:57:59.049Z

Reserved: 2026-08-19T21:47:08.936Z

Link: CVE-2026-76867

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T22:17:01.500

Modified: 2026-09-16T19:47:01.197

Link: CVE-2026-76867

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T21:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')