CVE-2026-108908 | Netcore NR268 1.7.121109 Web UI l7_call_board_user_set.cgi eval title/note/URL/content cross site scripting

SecurityVulns

A vulnerability was found in Netcore NR268 1.7.121109. It has been declared as problematic. Affected by this vulnerability is the function eval of the file /router/l7_call_board_user_set.cgi of the component Web UI. Such manipulation of the argument title/note/URL/content leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2026-108908. The attack can be launched remotely. Moreover, an exploit is present.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More