Impact
Netcore NR255‑V version 1.5.130703 contains a stored cross‑site scripting vulnerability in DHCP static IP and IP ACL management pages, including dhcp_add_staticip_cgi, dhcp_staticip_show_cgi, ip_acl_set_cgi, and ip_acl_show_cgi. By injecting persistent malicious scripts into these components, attackers can compromise the web management interface for other users, allowing potentially malicious code to execute when the interface is viewed.
Affected Systems
The affected product is Netcore NR255‑V, specifically firmware version 1.5.130703. No additional version details are provided.
Risk and Exploitability
The vulnerability has a CVSS score of 5.1, indicating moderate severity. The EPSS score is less than 1%, implying a low but non‑zero likelihood of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector requires access to the web interface, which may be achieved locally or remotely over the network, as inferred from the references provided.
OpenCVE Enrichment