CVE-2026-76855
nicheCross-User Session & Browsing History Disclosure in Netcore NR255-V Audit Endpoints
Netcore's NR255-V router, running firmware version 1.5.130703, exposes a sensitive information disclosure flaw (CWE-359) in its web-based audit subsystem, specifically the endpoints implemented in l7_web_auth_log_dump_cgi.c, audit_get_cgi.c, and mod_dispatch_auth/plan.. A low-privileged authenticated attacker on the router's web interface can query these audit components over the network with low complexity and retrieve other users' session data and browsing history, including records spanning past sessions. Successful abuse enables cross-user session hijacking and silent surveillance of victim browsing activity, with high confidentiality impact but no direct effect on integrity or availability. Organizations running the NR255-V on this firmware are affected; no public proof of concept is known, the flaw is not in the CISA KEV catalog, and there is no evidence of in-the-wild exploitation to date.
What to do: Restrict the NR255-V management/audit web interface to trusted LAN or VPN segments and never expose it to the internet, since exploitation only requires a low-privileged web account. Contact Netcore for a firmware newer than 1.5.130703, and given the age of this build (July 2013), plan to retire or replace the device if no patched release exists. Review audit log access records for unexpected queries against the audit/log-dump endpoints and rotate user sessions and credentials if anomalous access is found.
| Netcore NR255-V | 1.5.130703 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the audit endpoints handled by l7_web_auth_log_dump_cgi.c, audit_get_cgi.c, and mod_dispatch_auth/plan.json. Attackers can query these audit components to obtain other users' session and browsing history data across sessions.
- Weakness
- CWE-359
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.