ZeroHour

CVE-2026-76859

niche

Router Credential Disclosure via user_pass_show.cgi in Netcore NR255-V

CVSS 4.0
7.1 high
EPSS
Published
()
Modified
AI analysis

Netcore NR255-V router firmware version 1.5.130703 contains a sensitive information disclosure vulnerability (CWE-522, insufficiently protected credentials) in the user_pass_show.cgi component. An attacker with only low-privilege (non-admin) access to the router's web management interface can leverage the ui_config_2.xml configuration endpoint and misc.js to retrieve stored router credentials, exposing the administrative login. Successful exploitation gives the attacker full administrative control of the device, enabling traffic interception, configuration changes, and pivot access to the internal network. Only NR255-V running version 1.5.130703 is confirmed affected; no fixed version has been publicly specified in the available data. There is no known public proof-of-concept and no evidence of exploitation in the wild, and the flaw is not on the CISA Known Exploited Vulnerabilities list.

What to do: Contact Netcore for a firmware version newer than 1.5.130703 that removes credential exposure from user_pass_show.cgi; if no patch exists, restrict the web management interface to trusted LAN/VPN access only so low-privilege or remote users cannot reach the endpoint. Rotate the router's administrative and any user account passwords, treating existing credentials as potentially disclosed if low-privilege accounts existed or the management interface was remotely reachable.

Affected
Netcore NR255-V1.5.130703
Estimated exposure
nichelikely hundreds to low thousands of devices (unknown exact count) — The NR255-V is an older, China-market-focused Netcore enterprise VPN router typically deployed in SMBs, so the internet-exposed population is plausibly in the low thousands based on typical deployment patterns for this vendor's product…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the user_pass_show.cgi component. Low-privilege attackers can exploit this flaw via ui_config_2.xml and misc.js to disclose router credentials.

Weakness
CWE-522
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.