CVE-2026-76859
nicheRouter Credential Disclosure via user_pass_show.cgi in Netcore NR255-V
Netcore NR255-V router firmware version 1.5.130703 contains a sensitive information disclosure vulnerability (CWE-522, insufficiently protected credentials) in the user_pass_show.cgi component. An attacker with only low-privilege (non-admin) access to the router's web management interface can leverage the ui_config_2.xml configuration endpoint and misc.js to retrieve stored router credentials, exposing the administrative login. Successful exploitation gives the attacker full administrative control of the device, enabling traffic interception, configuration changes, and pivot access to the internal network. Only NR255-V running version 1.5.130703 is confirmed affected; no fixed version has been publicly specified in the available data. There is no known public proof-of-concept and no evidence of exploitation in the wild, and the flaw is not on the CISA Known Exploited Vulnerabilities list.
What to do: Contact Netcore for a firmware version newer than 1.5.130703 that removes credential exposure from user_pass_show.cgi; if no patch exists, restrict the web management interface to trusted LAN/VPN access only so low-privilege or remote users cannot reach the endpoint. Rotate the router's administrative and any user account passwords, treating existing credentials as potentially disclosed if low-privilege accounts existed or the management interface was remotely reachable.
| Netcore NR255-V | 1.5.130703 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the user_pass_show.cgi component. Low-privilege attackers can exploit this flaw via ui_config_2.xml and misc.js to disclose router credentials.
- Weakness
- CWE-522
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.