CVE-2026-76867

Netcore NR255-V firmware version 1.5.130703 contains a stored cross-site scripting vulnerability in routing and NAT configuration CGI components including routing_tab_add_cgi, routing_table_list_show_cgi, route_policy_add_cgi, and route_policy_parame_show_cgi. Attackers can inject persistent script payloads through these route and NAT configuration pages, which are then executed in the context of users viewing the affected pages.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-15 22:17

Updated : 2026-09-15 22:17


NVD link : CVE-2026-76867

Mitre link : CVE-2026-76867

CVE.ORG link : CVE-2026-76867


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')