Nexxt Solutions NCM-X1800 Mesh Router Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in the Nexxt Solutions NCM-X1800 Mesh Router, specifically in firmware versions UV1.2.7 and below. This vulnerability allows attackers to inject JavaScript that is executed in the context of administrator sessions. The issue arises in the device management page, where the DEVICE_ALIAS parameter is sent to the /web/um_device_set_aliasname endpoint.

Impact

Exploitation of this vulnerability could lead to session hijacking, credential theft, or unauthorized actions being performed as an administrator.

Reproduction

To reproduce this vulnerability, log into the Nexxt Solutions NCM-X1800 Mesh Router with an administrator account. Navigate to the device management page and use the alias feature to inject a JavaScript payload into the DEVICE_ALIAS parameter. Once the alias is set, the injected script will execute when the device management page is viewed, taking place within the context of the admin session.

Added: Jul 15, 2025, 3:32 PM
Updated: Jul 15, 2025, 3:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.4
exploitability
5.9
remediation
0.0
relevance
0.3
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.