Executive brief
Netcore NR255-V is a network router used to manage and control layer-7 content policies and call board configurations. A stored cross-site scripting vulnerability allows authenticated attackers to inject malicious scripts into management pages that execute when other administrators view the compromised content, potentially leading to credential theft, unauthorized configuration changes, or lateral movement within the network.
Technical details
This is a stored cross-site scripting (CWE-79) vulnerability in the L7 content management pages of Netcore NR255-V v1.5.130703, specifically affecting the call board text and policy group handling components. The vulnerability exists because user input is passed directly to eval() sinks without proper sanitization or escaping. The attack requires authentication to the management interface and user interaction (viewing the affected page), but once injected, the malicious script persists and executes in the context of any administrator viewing that content. An attacker with management access can achieve session hijacking, credential disclosure, or unauthorized configuration changes. No patch status is currently documented.
Affected products
- Netcore NR255-V 1.5.130703
Timeline
- 2026-09-04: disclosed
- 2026-09-15: advisory