CVE-2026-76858
MEDIUM
NVD
CVSS Score
4.8
Severity
MEDIUM
Published
Sep 15, 2026
Vendor
unknown
Description
Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in ddns_wan_list_show.cgi caused by unsafe eval() handling of DDNS data. Attackers can inject malicious script through the DDNS configuration path, leading to persistent execution when the affected page is viewed.