CVE-2026-76872: Netcore NR255-V

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in DHCP static IP and IP ACL management pages, including dhcp_add_staticip_cgi, dhcp_staticip_show_cgi, ip_acl_set_cgi, and ip_acl_show_cgi. Attackers can inject persistent malicious scripts through these components to compromise the web management interface for other users.'

Affected products

  • Netcore NR255-V: version 1.5.130703 only

Published 2026-09-15. Last modified 2026-09-17.