Description
Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages that use eval() sinks, affecting the call board text and policy group handling components. Attackers can inject persistent script payloads through these pages to have malicious code executed in the context of other users viewing the affected content.
Published: 2026-09-15
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting affecting user browsers
Action: Apply Patch
AI Analysis

Impact

Netcore NR255-V routers running firmware 1.5.130703 expose a stored cross‑site scripting flaw in the Layer 7 content management interface. By inserting malicious JavaScript into the call board text or policy group pages, an attacker can embed persistent code that will execute in any user’s browser when they view the affected content. Based on the description, it is inferred that this client‑side execution could lead to credential theft, session hijacking, or the delivery of additional malware, and it may occur without the need for user interaction beyond loading the page.

Affected Systems

The vulnerability exists in Netcore’s NR255-V router model running firmware version 1.5.130703, the L7 content management pages that process user‑supplied text for call boards and policy groups.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate impact, and the EPSS score of less than 1 % suggests low likelihood of widespread exploitation at present. The flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires an attacker to have access to the router’s content management interface, typically through privileged network access or by compromising credentials. Based on the description, it is inferred that once injected, the payload is stored and executed whenever privileged users view the page, limiting the attack surface to those users.

Generated by OpenCVE AI on September 16, 2026 at 21:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router firmware to a version that removes the eval() sinks in the L7 content management pages.
  • If an upgrade is not immediately available, restrict access to the content management interface to a trusted administrator network segment and disable or remove the eval‑based pages.
  • Deploy a web application firewall or enforce a strict Content Security Policy that blocks inline scripts and alerts on eval usage as a temporary mitigation.

Generated by OpenCVE AI on September 16, 2026 at 21:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages that use eval() sinks, affecting the call board text and policy group handling components. Attackers can inject persistent script payloads through these pages to have malicious code executed in the context of other users viewing the affected content.
Title Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting in L7 Content Management via eval() Sinks
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T21:58:05.366Z

Reserved: 2026-09-15T21:09:51.279Z

Link: CVE-2026-92257

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-15T22:17:04.740

Modified: 2026-09-15T22:17:04.740

Link: CVE-2026-92257

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T21:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')