ZeroHour

CVE-2026-76854

niche

Captive-Portal Credential Disclosure in Netcore NR255-V Router (l7_web_auth_user_show.cgi)

CVSS 4.0
7.1 high
EPSS
Published
()
Modified
AI analysis

Netcore NR255-V router firmware version 1.5.130703 contains a sensitive information disclosure vulnerability (CWE-522, insufficiently protected credentials) in the l7_web_auth_user_show.cgi component, which handles captive-portal user data. A remote attacker with low privileges (per the CVSS 4.0 vector, PR:L) can query this CGI endpoint over the network and retrieve captive-portal user credentials. Successful exploitation compromises the confidentiality of authenticated network access, allowing an attacker to impersonate portal users and gain network access under their accounts. Organizations running the affected NR255-V firmware with the captive portal feature enabled are exposed. No public proof-of-concept exists and the flaw is not listed in the CISA KEV catalog, so exploitation is currently unknown.

What to do: Restrict access to the router's web management interface and CGI endpoints (including l7_web_auth_user_show.cgi) to trusted internal networks or a management VLAN, and verify firewall rules do not expose management to the internet. Contact Netcore for a fixed firmware version for the NR255-V, as no patched version is specified in the advisory. If the captive portal is or was in use, rotate all portal user credentials and review authentication logs for unexplained queries to the affected endpoint.

Affected
Netcore NR255-V1.5.130703
Estimated exposure
nicheunknown precise count; likely thousands or fewer internet-exposed NR255-V units, within Netcore's broader internet-exposed router footprint — Netcore/netis routers commonly appear in public internet scans (Shodan/Censys) in the tens of thousands range overall, but no model-specific count for the NR255-V enterprise router was available, so this is a rough extrapolation.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l7_web_auth_user_show.cgi related to captive-portal credential handling. Attackers can query this component to obtain captive-portal user credentials, compromising confidentiality of authenticated network access.

Weakness
CWE-522
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.