Stored Cross-Site Scripting in Netcore NR255-V Router Firmware
CVE-2026-76867

5.1MEDIUM

Key Information:

Vendor

Netcore

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-76867?

The Netcore NR255-V router firmware version 1.5.130703 is impacted by a stored cross-site scripting vulnerability within its routing and NAT configuration components. This vulnerability allows attackers to inject malicious script payloads through the routing_tab_add_cgi, routing_table_list_show_cgi, route_policy_add_cgi, and route_policy_parame_show_cgi pages. When users access these pages, the injected scripts execute in their browsers, potentially compromising their data and session information.

Affected Version(s)

NR255-V 1.5.130703

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zhou Ao
Yin Luxing
Jiang Yuxuan
Liu Xin
@Nebusec
.