Stored Cross-Site Scripting Vulnerability in Netcore NR255-V
CVE-2026-76864

4.8MEDIUM

Key Information:

Vendor

Netcore

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-76864?

The NR255-V version 1.5.130703 has a vulnerability where it fails to properly sanitize Quality of Service (QoS) rule names prior to parsing them using eval() in various handlers. This oversight allows attackers to inject persistent script code through maliciously crafted QoS rule names. When the stored data is subsequently processed by the affected handlers, the injected script executes, which could potentially compromise the integrity of the system and lead to unauthorized actions or data exposure.

Affected Version(s)

NR255-V 1.5.130703

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zhou Ao
Yin Luxing
Jiang Yuxuan
Liu Xin
@Nebusec
.