Description
Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in DHCP static IP and IP ACL management pages, including dhcp_add_staticip_cgi, dhcp_staticip_show_cgi, ip_acl_set_cgi, and ip_acl_show_cgi. Attackers can inject persistent malicious scripts through these components to compromise the web management interface for other users.'
Published: 2026-09-15
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

Netcore NR255‑V version 1.5.130703 contains a stored cross‑site scripting vulnerability in DHCP static IP and IP ACL management pages, including dhcp_add_staticip_cgi, dhcp_staticip_show_cgi, ip_acl_set_cgi, and ip_acl_show_cgi. By injecting persistent malicious scripts into these components, attackers can compromise the web management interface for other users, allowing potentially malicious code to execute when the interface is viewed.

Affected Systems

The affected product is Netcore NR255‑V, specifically firmware version 1.5.130703. No additional version details are provided.

Risk and Exploitability

The vulnerability has a CVSS score of 5.1, indicating moderate severity. The EPSS score is less than 1%, implying a low but non‑zero likelihood of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector requires access to the web interface, which may be achieved locally or remotely over the network, as inferred from the references provided.

Generated by OpenCVE AI on September 18, 2026 at 13:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and install the latest firmware from Netcore that addresses the stored cross‑site scripting flaw in the DHCP and IP ACL management pages.
  • Restrict access to the DHCP/static IP and IP ACL configuration pages to authorized administrative users, enforce strong authentication and network segmentation.
  • Deploy a web application firewall or implement server‑side input sanitization to block malicious script payloads that might be submitted through these management pages.

Generated by OpenCVE AI on September 18, 2026 at 13:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Netcore
Netcore nr255-v
Vendors & Products Netcore
Netcore nr255-v

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in DHCP static IP and IP ACL management pages, including dhcp_add_staticip_cgi, dhcp_staticip_show_cgi, ip_acl_set_cgi, and ip_acl_show_cgi. Attackers can inject persistent malicious scripts through these components to compromise the web management interface for other users.'
Title Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting via DHCP/ACL Management Pages
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T16:55:25.813Z

Reserved: 2026-08-19T21:47:08.936Z

Link: CVE-2026-76872

cve-icon Vulnrichment

Updated: 2026-09-17T16:55:21.207Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T22:17:02.390

Modified: 2026-09-17T17:16:47.787

Link: CVE-2026-76872

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T13:30:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')