CVE-2026-92256
nicheLow-Privilege Info Disclosure in NR255-V Router Leaks IPsec PSK and RSA Keys
The NR255-V router firmware version 1.5.130703 contains a sensitive information disclosure flaw (CWE-522) in its web-based read handlers, specifically l2tpd_config_show_cgi.c, ipsec_show_cgi.c, and the mod_vpn_remote/plan. handler. A remote attacker with low-privilege access to the device's management interface can query l2tpd_config_show.cgi and retrieve stored IPsec pre-shared keys (PSKs) and RSA key material. With these credentials, an attacker could impersonate VPN endpoints, decrypt captured VPN traffic, or pivot into the site-to-site or remote-access VPNs the device terminates. The flaw affects devices running exactly version 1.5.130703 of the NR255-V firmware, with no fix specified in the advisory data. There is no public proof-of-concept and no indication of exploitation in the wild; the issue is not on the CISA Known Exploited Vulnerabilities list.
What to do: Upgrade NR255-V devices off version 1.5.130703 as soon as a vendor firmware fix is available, and in the meantime restrict the web management interface to a trusted management network or VPN rather than exposing it to the internet. Rotate all IPsec pre-shared keys and regenerate/replace RSA key material stored on the device, since previously exposed keys should be considered compromised. Review VPN logs and firewall rules for unexpected access to the CGI endpoints or unexplained VPN sessions.
| NR255-V router/VPN gateway firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l2tpd_config_show_cgi.c, ipsec_show_cgi.c, and mod_vpn_remote/plan.json read handlers. Attackers can query l2tpd_config_show.cgi to expose stored IPsec PSK and RSA key material.
- Weakness
- CWE-522
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.