GHSA-2fvm-cppx-f9c5MediumCVSS 5.2
Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in the...
🔗 CVE IDs covered (1)
📋 Description
Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in the DHCP dynamic IP display and ARP bind list display components handling hostname fields. A LAN-based attacker can inject malicious script through these hostname fields, which is later rendered by network_config.js and network_security.js in the web management interface.
🔗 References (4)
- https://nvd.nist.gov/vuln/detail/CVE-2026-76873
- https://github.com/draw-ctf/netcore-router-public-refs/blob/main/2026.08.19-netcore-nr255v-dhcp-lan-xss.md
- https://www.vulncheck.com/advisories/netcore-nr255-v-1.5.130703-stored-cross-site-scripting-via-dhcp-and-arp-hostname-fields
- https://github.com/advisories/GHSA-2fvm-cppx-f9c5