Executive brief
The Netcore NR255-V is a wireless router used in home and small business networks. A vulnerability in its web-based DDNS (Dynamic DNS) configuration interface allows attackers who can access the router's admin panel to inject malicious code that persists and executes whenever any administrator views the affected DDNS configuration page, potentially compromising the router's settings or the administrator's session.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in the ddns_wan_list_show.cgi web interface component, caused by unsafe eval() handling of DDNS configuration data. An attacker with administrative access to the router can inject malicious JavaScript through the DDNS configuration path, which is stored and reflected when the page is accessed. The attack requires high privilege (admin login) and user interaction (viewing the DDNS page), but once injected, the malicious script persists and executes in the browser context of any administrator who views the affected page. No patch information is currently available.
Affected products
- Netcore NR255-V 1.5.130703
Timeline
- 2026-09-04: disclosed
- 2026-09-15: advisory