Impact
Netcore NR255-V routers running firmware 1.5.130703 expose a stored cross‑site scripting flaw in the Layer 7 content management interface. By inserting malicious JavaScript into the call board text or policy group pages, an attacker can embed persistent code that will execute in any user’s browser when they view the affected content. Based on the description, it is inferred that this client‑side execution could lead to credential theft, session hijacking, or the delivery of additional malware, and it may occur without the need for user interaction beyond loading the page.
Affected Systems
The vulnerability exists in Netcore’s NR255-V router model running firmware version 1.5.130703, the L7 content management pages that process user‑supplied text for call boards and policy groups.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate impact, and the EPSS score of less than 1 % suggests low likelihood of widespread exploitation at present. The flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires an attacker to have access to the router’s content management interface, typically through privileged network access or by compromising credentials. Based on the description, it is inferred that once injected, the payload is stored and executed whenever privileged users view the page, limiting the attack surface to those users.
OpenCVE Enrichment