CVE-2026-92257
Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting in L7 Content Management via eval() Sinks
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages that use eval() sinks, affecting the call board text and policy group handling components. Attackers can inject persistent script payloads through these pages to have malicious code executed in the context of other users viewing the affected content.
| CWE | CWE-79 |
| Vendor | netcore |
| Product | nr255-v |
| Published | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for netcore nr255-v
Be the first to know when new medium vulnerabilities affecting netcore nr255-v are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
Netcore / NR255-V
1.5.130703
References
Credits
Zhou Ao Yin Luxing Jiang Yuxuan Liu Xin @Nebusec