ZeroHour

CVE-2026-76857

niche

Plaintext DDNS Credential Disclosure in Netcore NR255-V Router Firmware

CVSS 4.0
7.1 high
EPSS
Published
()
Modified
AI analysis

Netcore NR255-V routers running firmware 1.5.130703 store and return DDNS (dynamic DNS) credentials in plaintext through the ddns_wan_list_show.cgi CGI endpoint, with related exposure in the DDNSset_cgi, IGD_GetCgiHandler, and IGD_CgiCall components (CWE-522). An attacker who reaches this CGI handler with low privileges (the CVSS 4.0 vector requires PR:L, suggesting an authenticated or low-privilege session) can retrieve the router's configured DDNS usernames and passwords in cleartext. This exposes the victim's DDNS provider account, potentially allowing account takeover, DNS hijacking of the associated domain, and lateral reuse of those credentials if they are shared elsewhere. The flaw is rated 7.1 (high) under CVSS 4.0. It is not listed in CISA's KEV catalog, no public proof-of-concept is known, and there is no evidence of exploitation in the wild.

What to do: Contact Netcore for a firmware update and upgrade the NR255-V off version 1.5.130703 as soon as a fixed build is available. Immediately rotate the DDNS provider credentials configured on any affected unit and review that DDNS account for unauthorized changes. Restrict the router's web/CGI management interface to trusted LAN or VPN access and never expose it directly to the internet.

Affected
Netcore NR255-Vfirmware 1.5.130703
Estimated exposure
nichelikely hundreds to low thousands of devices (no public scan counts for this model) — The NR255-V is a legacy enterprise router (the firmware build string 130703 indicates a 2013-era release) primarily distributed in the Chinese market, and no public internet-scan or deployment counts specific to this model are available,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Netcore NR255-V firmware version 1.5.130703 contains a sensitive information disclosure vulnerability in the ddns_wan_list_show.cgi endpoint and related DDNSset_cgi, IGD_GetCgiHandler, and IGD_CgiCall components. Attackers who reach this CGI handler can obtain plaintext DDNS credentials, exposing sensitive account information.

Weakness
CWE-522
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.