Description
Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the user_pass_show.cgi component. Low-privilege attackers can exploit this flaw via ui_config_2.xml and misc.js to disclose router credentials.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

Netcore NR255-V routers running firmware 1.5.130703 contain a flaw in the user_pass_show.cgi component that permits disclosure of stored router credentials. The vulnerability is triggered when a user with low privileges interacts with the ui_config_2.xml configuration file and the supporting misc.js script, allowing the attacker to extract the administrative username and password. This compromises the confidentiality of the device’s management interface, potentially enabling further network compromise if the credentials are reused.

Affected Systems

The affected device is the Netcore NR255‑V router with firmware build 1.5.130703. No other vendors, products, or firmware versions are listed as affected in the available data. All installations of this firmware should be examined for exposure to this flaw.

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact, and the EPSS score of less than 1% suggests that exploitation is unlikely to be widespread but still possible. The vulnerability is not listed in the CISA KEV catalog. Exploitation appears to require only local or remote access to the router’s configuration interface and does not require privileged credentials, making it relatively easy for an attacker who can reach the device network.

Generated by OpenCVE AI on September 18, 2026 at 13:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Netcore firmware update that includes a fix for user_pass_show.cgi and related files.
  • If a firmware upgrade cannot be performed immediately, restrict local network access to the router’s management interface and disable remote administration until a patch is applied.
  • Remove or disable the ui_config_2.xml and misc.js components that expose credentials, or block their access with firewall rules.

Generated by OpenCVE AI on September 18, 2026 at 13:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Netcore
Netcore nr255-v
Vendors & Products Netcore
Netcore nr255-v
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the user_pass_show.cgi component. Low-privilege attackers can exploit this flaw via ui_config_2.xml and misc.js to disclose router credentials.
Title Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via user_pass_show.cgi
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:27:16.961Z

Reserved: 2026-08-19T21:47:08.935Z

Link: CVE-2026-76859

cve-icon Vulnrichment

Updated: 2026-09-17T19:16:32.555Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T22:17:00.120

Modified: 2026-09-17T20:18:15.757

Link: CVE-2026-76859

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T13:30:09Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials