CVE-2026-76858

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in ddns_wan_list_show.cgi caused by unsafe eval() handling of DDNS data. Attackers can inject malicious script through the DDNS configuration path, leading to persistent execution when the affected page is viewed.

  • Published Sep 15, 2026
  • CVSS 4.8 medium
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-76858 at the National Vulnerability Database