ZeroHour

CVE-2026-92256

niche

Low-Privilege Info Disclosure in NR255-V Router Leaks IPsec PSK and RSA Keys

CVSS 4.0
7.1 high
EPSS
Published
()
Modified
AI analysis

The NR255-V router firmware version 1.5.130703 contains a sensitive information disclosure flaw (CWE-522) in its web-based read handlers, specifically l2tpd_config_show_cgi.c, ipsec_show_cgi.c, and the mod_vpn_remote/plan. handler. A remote attacker with low-privilege access to the device's management interface can query l2tpd_config_show.cgi and retrieve stored IPsec pre-shared keys (PSKs) and RSA key material. With these credentials, an attacker could impersonate VPN endpoints, decrypt captured VPN traffic, or pivot into the site-to-site or remote-access VPNs the device terminates. The flaw affects devices running exactly version 1.5.130703 of the NR255-V firmware, with no fix specified in the advisory data. There is no public proof-of-concept and no indication of exploitation in the wild; the issue is not on the CISA Known Exploited Vulnerabilities list.

What to do: Upgrade NR255-V devices off version 1.5.130703 as soon as a vendor firmware fix is available, and in the meantime restrict the web management interface to a trusted management network or VPN rather than exposing it to the internet. Rotate all IPsec pre-shared keys and regenerate/replace RSA key material stored on the device, since previously exposed keys should be considered compromised. Review VPN logs and firewall rules for unexpected access to the CGI endpoints or unexplained VPN sessions.

Affected
NR255-V router/VPN gateway firmware
Estimated exposure
nichelikely low thousands of devices or fewer (exact count unknown) — No public install counts or scan data were provided; the flaw is limited to a single legacy router/VPN gateway model, which typically exists in small-business deployments numbering in the hundreds to low thousands of units.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l2tpd_config_show_cgi.c, ipsec_show_cgi.c, and mod_vpn_remote/plan.json read handlers. Attackers can query l2tpd_config_show.cgi to expose stored IPsec PSK and RSA key material.

Weakness
CWE-522
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.