Impact
Netcore NR255‑V firmware version 1.5.130703 contains a web‑based component that exposes DDNS credentials in clear text. The vulnerability arises in the ddns_wan_list_show.cgi endpoint and related DDNSset_cgi, IGD_GetCgiHandler, and IGD_CgiCall components, permitting any user who can reach the CGI handler to read private account usernames and passwords. This weakness is classified as CWE‑522, Sensitive Information Exposure, and is assessed with a CVSS score of 7.1, indicating a high severity impact on confidentiality.
Affected Systems
The flaw affects Netcore routers that run the NR255‑V firmware version 1.5.130703. No other firmware revisions are reported to contain or fix this issue. Network administrators should verify that their devices are operating on this specific build and determine whether any unpatched or older units remain in use.
Risk and Exploitability
The CVSS score of 7.1 denotes a significant risk to the confidentiality of DDNS account data when an attacker can reach the vulnerable CGI endpoint. The EPSS score of less than 1 % indicates that exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation. Nonetheless, once an attacker obtains access to the router’s web administration interface—either locally or via remote management—the credential disclosure is straightforward. The likely attack path involves navigating to the ddns_wan_list_show.cgi URL, which is typically exposed as part of the router’s standard web interface and may not require authentication in default configurations.
OpenCVE Enrichment