Description
Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l7_web_auth_user_show.cgi related to captive-portal credential handling. Attackers can query this component to obtain captive-portal user credentials, compromising confidentiality of authenticated network access.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The Netcore NR255-V version 1.5.130703 contains a missing access control flaw in the l7_web_auth_user_show.cgi script that allows an attacker to query the component and retrieve captive‑portal user credentials, compromising the confidentiality of network access for users connected through the portal and is classified as CWE‑522, data exposure.

Affected Systems

Netcore NR255-V, version 1.5.130703 is affected by this vulnerability. No other versions or products are listed as impacted.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑to‑high severity of the information disclosure. The EPSS score is less than 1 %, suggesting a very low probability of exploitation at this time, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is a remote HTTP request to the l7_web_auth_user_show.cgi endpoint, which, if exposed publicly, could be used by an attacker to harvest captive‑portal credentials.

Generated by OpenCVE AI on September 16, 2026 at 20:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Netcore NR255-V firmware to a version that resolves the credential disclosure vulnerability.
  • Restrict network access to the l7_web_auth_user_show.cgi endpoint so it is no longer publicly reachable.
  • If possible, reconfigure the captive‑portal login to use strong, non‑default credentials and consider disabling the exposed CGI script until a patch is applied.

Generated by OpenCVE AI on September 16, 2026 at 20:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l7_web_auth_user_show.cgi related to captive-portal credential handling. Attackers can query this component to obtain captive-portal user credentials, compromising confidentiality of authenticated network access.
Title Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via l7_web_auth_user_show.cgi
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T21:57:50.108Z

Reserved: 2026-08-19T21:47:08.935Z

Link: CVE-2026-76854

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T22:16:59.250

Modified: 2026-09-16T19:47:01.197

Link: CVE-2026-76854

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T20:45:05Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials