CVE-2026-76873
Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting via DHCP and ARP Hostname Fields
CVSS Score
5.2
EPSS Score
0.0%
EPSS Percentile
0th
Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in the DHCP dynamic IP display and ARP bind list display components handling hostname fields. A LAN-based attacker can inject malicious script through these hostname fields, which is later rendered by network_config.js and network_security.js in the web management interface.
| CWE | CWE-79 |
| Vendor | netcore |
| Product | nr255-v |
| Published | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for netcore nr255-v
Be the first to know when new medium vulnerabilities affecting netcore nr255-v are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
Netcore / NR255-V
1.5.130703
References
Credits
Zhou Ao Yin Luxing Jiang Yuxuan Liu Xin @Nebusec