CVE-2026-76858
Received Received - Intake

Stored XSS in Netcore NR255-V Router via DDNS Configuration

Vulnerability report for CVE-2026-76858, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: VulnCheck

Description

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in ddns_wan_list_show.cgi caused by unsafe eval() handling of DDNS data. Attackers can inject malicious script through the DDNS configuration path, leading to persistent execution when the affected page is viewed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
netcore nr255-v 1.5.130703

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stored cross-site scripting (XSS) flaw in Netcore NR255-V version 1.5.130703. It exists in the ddns_wan_list_show.cgi component due to unsafe handling of DDNS data using eval(). Attackers can inject malicious scripts via the DDNS configuration path, which then execute persistently when the affected page is viewed.

Detection Guidance

To detect this vulnerability, inspect the DDNS configuration settings in the Netcore NR255-V device for any unusual or malicious scripts in the DDNS path. Check the ddns_wan_list_show.cgi page for stored scripts. No specific commands are provided in the context.

Impact Analysis

An attacker could steal session cookies, perform actions on your behalf, or redirect you to malicious sites. This could lead to unauthorized access to your device settings or network, compromise sensitive data, or enable further attacks within your network.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating GDPR's data protection requirements or HIPAA's safeguards for protected health information. Organizations may face compliance violations, legal penalties, or reputational damage if exploited.

Mitigation Strategies

Immediately update the Netcore NR255-V firmware to the latest version. Disable or restrict access to the ddns_wan_list_show.cgi page if not required. Review and sanitize any DDNS configuration data for malicious content. Monitor network traffic for unusual activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76858. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart