Netcore NR255-V firmware version 1.5.130703 contains a stored cross-site scripting vulnerability in routing and NAT configuration CGI components including routing_tab_add_cgi, routing_table_list_show_cgi, route_policy_add_cgi, and route_policy_parame_show_cgi. Attackers can inject persistent script payloads through these route and NAT configuration pages, which are then executed in the context of users viewing the affected pages.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-15 22:17
Updated : 2026-09-15 22:17
NVD link : CVE-2026-76867
Mitre link : CVE-2026-76867
CVE.ORG link : CVE-2026-76867
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
