Impact
Netcore NR255-V router version 1.5.130703 is vulnerable to stored cross‑site scripting. The flaw resides in the DHCP dynamic IP display and ARP bind list modules that process hostname fields. An attacker can insert malicious script into these fields, which is later rendered by the web management interface scripts. An exploited instance would allow the attacker to run code in the context of the router’s web UI, potentially leaking session data, defacing the interface, or hijacking administrative sessions.
Affected Systems
Only the Netcore NR255‑V line of routers running firmware version 1.5.130703 is affected. No other Netcore models or firmware revisions are listed as vulnerable. The issue is confined to the DHCP and ARP hostname configuration controls exposed through the LAN‑side management console.
Risk and Exploitability
The CVSS v3 score of 5.1 indicates a moderate severity, and the EPSS value of less than 1 % implies a very low current exploitation probability. The vulnerability is not currently listed in the CISA KEV catalogue. Because the attack requires local network access to inject the payload into the hostname fields, it is limited to attackers who can contact the router over the LAN or rely on weak or unprotected remote management ports. An attacker would need to manipulate DHCP or ARP configurations directly; no public remote exploitation path is described.
OpenCVE Enrichment