VYPR

NR255-V

by Netcore

CVEs (23)

  • CVE-2026-76864MedSep 15, 2026
    risk 0.31cvss 4.8epss

    NR255-V version 1.5.130703 fails to sanitize QoS rule names before they are parsed via eval() in qos_xianz_add_cgi, qos_xianz_show_cgi, qos_filter_add_cgi, and qos_filter_show_cgi handlers. An attacker can inject persistent script code through crafted QoS rule name input that…

  • CVE-2026-76858MedSep 15, 2026
    risk 0.31cvss 4.8epss

    Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in ddns_wan_list_show.cgi caused by unsafe eval() handling of DDNS data. Attackers can inject malicious script through the DDNS configuration path, leading to persistent execution when the…

  • CVE-2026-76863MedSep 15, 2026
    risk 0.28cvss 4.3epss

    Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the mod_qos_bandwidth plan.json handling within filter_conns_dump_cgi.c and IGD_CgiCall.c. Authenticated users with broad roles can access these QoS read routes to obtain live network…

Page 2 of 2