Description
Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in DHCP static IP and IP ACL management pages, including dhcp_add_staticip_cgi, dhcp_staticip_show_cgi, ip_acl_set_cgi, and ip_acl_show_cgi. Attackers can inject persistent malicious scripts through these components to compromise the web management interface for other users.'
Published: 2026-09-15
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

Netcore NR255‑V version 1.5.130703 contains a stored cross‑site scripting vulnerability in DHCP static IP and IP ACL management pages, including dhcp_add_staticip_cgi, dhcp_staticip_show_cgi, ip_acl_set_cgi, and ip_acl_show_cgi. By injecting persistent malicious scripts into these components, attackers can compromise the web management interface for other users, allowing potentially malicious code to execute when the interface is viewed.

Affected Systems

The affected product is Netcore NR255‑V, specifically firmware version 1.5.130703. No additional version details are provided.

Risk and Exploitability

The vulnerability has a CVSS score of 5.1, indicating moderate severity. The EPSS score is less than 1%, implying a low but non‑zero likelihood of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector requires access to the web interface, which may be achieved locally or remotely over the network, as inferred from the references provided.

Generated by OpenCVE AI on September 16, 2026 at 21:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest firmware from Netcore that addresses the stored cross‑site scripting flaw in the DHCP and IP ACL management pages.
  • Restrict access to the DHCP/static IP and IP ACL configuration pages to authorized administrative users, enforce strong authentication and network segmentation.
  • Deploy a web application firewall or implement server‑side input sanitization to block malicious script payloads that might be submitted through these management pages.

Generated by OpenCVE AI on September 16, 2026 at 21:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in DHCP static IP and IP ACL management pages, including dhcp_add_staticip_cgi, dhcp_staticip_show_cgi, ip_acl_set_cgi, and ip_acl_show_cgi. Attackers can inject persistent malicious scripts through these components to compromise the web management interface for other users.'
Title Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting via DHCP/ACL Management Pages
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T21:58:02.508Z

Reserved: 2026-08-19T21:47:08.936Z

Link: CVE-2026-76872

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T22:17:02.390

Modified: 2026-09-16T19:47:01.197

Link: CVE-2026-76872

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T21:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')