Stored Cross-Site Scripting Vulnerability in Netcore NR255-V
CVE-2026-76864
4.8MEDIUM
What is CVE-2026-76864?
The NR255-V version 1.5.130703 has a vulnerability where it fails to properly sanitize Quality of Service (QoS) rule names prior to parsing them using eval() in various handlers. This oversight allows attackers to inject persistent script code through maliciously crafted QoS rule names. When the stored data is subsequently processed by the affected handlers, the injected script executes, which could potentially compromise the integrity of the system and lead to unauthorized actions or data exposure.
Affected Version(s)
NR255-V 1.5.130703
References
CVSS V4
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Zhou Ao
Yin Luxing
Jiang Yuxuan
Liu Xin
@Nebusec
