Description
Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the audit endpoints handled by l7_web_auth_log_dump_cgi.c, audit_get_cgi.c, and mod_dispatch_auth/plan.json. Attackers can query these audit components to obtain other users' session and browsing history data across sessions.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply patch
AI Analysis

Impact

Netcore NR255‑V version 1.5.130703 exposes sensitive information through its audit endpoints, specifically those handled by l7_web_auth_log_dump_c and mod_dispatch_auth/plan.json. The flaw allows an attacker to request audit data and retrieve other users’ session identifiers and browsing history across different sessions. The weakness is classified as CWE‑359, a sensitive information disclosure.

Affected Systems

The vulnerability affects Netcore NR255‑V devices running firmware version 1.5.130703. No other versions or vendors are listed as impacted in the current advisory.

Risk and Exploitability

The CVSS score of 7.1 indicates significant impact, while the EPSS score of < 1% reflects a low probability of widespread exploitation. It is inferred that the audit endpoints are likely accessible via the router’s web interface, so an adversary with network access could, in theory, issue HTTP requests to these endpoints to extract the disclosed data. It is also inferred that no authentication requirement is needed to access these endpoints, as the description does not mention authentication.

Generated by OpenCVE AI on September 18, 2026 at 13:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Netcore firmware update that contains the fix for the audit endpoint disclosure.
  • Restrict network access to the audit endpoints by configuring firewall rules or IP access lists to limit connections to trusted management hosts.
  • If audit logging is not required, disable the auditing feature to eliminate the exposed endpoints.

Generated by OpenCVE AI on September 18, 2026 at 13:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Netcore
Netcore nr255-v
Vendors & Products Netcore
Netcore nr255-v

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the audit endpoints handled by l7_web_auth_log_dump_cgi.c, audit_get_cgi.c, and mod_dispatch_auth/plan.json. Attackers can query these audit components to obtain other users' session and browsing history data across sessions.
Title Netcore NR255-V 1.5.130703 Cross-User Session Disclosure via Audit Endpoints
Weaknesses CWE-359
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-16T19:30:07.791Z

Reserved: 2026-08-19T21:47:08.935Z

Link: CVE-2026-76855

cve-icon Vulnrichment

Updated: 2026-09-16T19:25:34.342Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T22:16:59.417

Modified: 2026-09-16T20:17:29.463

Link: CVE-2026-76855

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T14:00:10Z

Weaknesses
  • CWE-359

    Exposure of Private Personal Information to an Unauthorized Actor