CVE-2026-76857
nichePlaintext DDNS Credential Disclosure in Netcore NR255-V Router Firmware
Netcore NR255-V routers running firmware 1.5.130703 store and return DDNS (dynamic DNS) credentials in plaintext through the ddns_wan_list_show.cgi CGI endpoint, with related exposure in the DDNSset_cgi, IGD_GetCgiHandler, and IGD_CgiCall components (CWE-522). An attacker who reaches this CGI handler with low privileges (the CVSS 4.0 vector requires PR:L, suggesting an authenticated or low-privilege session) can retrieve the router's configured DDNS usernames and passwords in cleartext. This exposes the victim's DDNS provider account, potentially allowing account takeover, DNS hijacking of the associated domain, and lateral reuse of those credentials if they are shared elsewhere. The flaw is rated 7.1 (high) under CVSS 4.0. It is not listed in CISA's KEV catalog, no public proof-of-concept is known, and there is no evidence of exploitation in the wild.
What to do: Contact Netcore for a firmware update and upgrade the NR255-V off version 1.5.130703 as soon as a fixed build is available. Immediately rotate the DDNS provider credentials configured on any affected unit and review that DDNS account for unauthorized changes. Restrict the router's web/CGI management interface to trusted LAN or VPN access and never expose it directly to the internet.
| Netcore NR255-V | firmware 1.5.130703 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Netcore NR255-V firmware version 1.5.130703 contains a sensitive information disclosure vulnerability in the ddns_wan_list_show.cgi endpoint and related DDNSset_cgi, IGD_GetCgiHandler, and IGD_CgiCall components. Attackers who reach this CGI handler can obtain plaintext DDNS credentials, exposing sensitive account information.
- Weakness
- CWE-522
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.