Vulnerability Description
Netcore NR255-V firmware version 1.5.130703 contains a stored cross-site scripting vulnerability in routing and NAT configuration CGI components including routing_tab_add_cgi, routing_table_list_show_cgi, route_policy_add_cgi, and route_policy_parame_show_cgi. Attackers can inject persistent script payloads through these route and NAT configuration pages, which are then executed in the context of users viewing the affected pages.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/draw-ctf/netcore-router-public-refs/blob/main/2026.08.19-netc
- https://www.vulncheck.com/advisories/netcore-nr255-v-1.5.130703-stored-cross-sit
FAQ
What is CVE-2026-76867?
CVE-2026-76867 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Netcore NR255-V firmware version 1.5.130703 contains a stored cross-site scripting vulnerability in routing and NAT configuration CGI components including routing_tab_add_cgi, routing_table_list_show_...
How severe is CVE-2026-76867?
CVE-2026-76867 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-76867?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.