Description
Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the audit endpoints handled by l7_web_auth_log_dump_cgi.c, audit_get_cgi.c, and mod_dispatch_auth/plan.json. Attackers can query these audit components to obtain other users' session and browsing history data across sessions.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply patch
AI Analysis

Impact

Netcore NR255‑V version 1.5.130703 exposes sensitive information through its audit endpoints, specifically those handled by l7_web_auth_log_dump_c and mod_dispatch_auth/plan.json. The flaw allows an attacker to request audit data and retrieve other users’ session identifiers and browsing history across different sessions. The weakness is classified as CWE‑359, a sensitive information disclosure.

Affected Systems

The vulnerability affects Netcore NR255‑V devices running firmware version 1.5.130703. No other versions or vendors are listed as impacted in the current advisory.

Risk and Exploitability

The CVSS score of 7.1 indicates significant impact, while the EPSS score of < 1% reflects a low probability of widespread exploitation. The vulnerability is not listed in the CISA KE remote: the audit endpoints are accessible via the router’s web interface, so an adversary with network access can issue HTTP requests to these endpoints to extract the disclosed data. No authentication requirement is described.

Generated by OpenCVE AI on September 16, 2026 at 20:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Netcore firmware update that contains the fix for the audit endpoint disclosure.
  • Restrict network access to the audit endpoints by configuring firewall rules or IP access lists to limit connections to trusted management hosts.
  • If audit logging is not required, disable the auditing feature to eliminate the exposed endpoints.

Generated by OpenCVE AI on September 16, 2026 at 20:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the audit endpoints handled by l7_web_auth_log_dump_cgi.c, audit_get_cgi.c, and mod_dispatch_auth/plan.json. Attackers can query these audit components to obtain other users' session and browsing history data across sessions.
Title Netcore NR255-V 1.5.130703 Cross-User Session Disclosure via Audit Endpoints
Weaknesses CWE-359
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-16T19:30:07.791Z

Reserved: 2026-08-19T21:47:08.935Z

Link: CVE-2026-76855

cve-icon Vulnrichment

Updated: 2026-09-16T19:25:34.342Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T22:16:59.417

Modified: 2026-09-16T20:17:29.463

Link: CVE-2026-76855

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T21:00:08Z

Weaknesses
  • CWE-359

    Exposure of Private Personal Information to an Unauthorized Actor