Impact
Netcore NR255-V routers running firmware 1.5.130703 contain a flaw in the user_pass_show.cgi component that permits disclosure of stored router credentials. The vulnerability is triggered when a user with low privileges interacts with the ui_config_2.xml configuration file and the supporting misc.js script, allowing the attacker to extract the administrative username and password. This compromises the confidentiality of the device’s management interface, potentially enabling further network compromise if the credentials are reused.
Affected Systems
The affected device is the Netcore NR255‑V router with firmware build 1.5.130703. No other vendors, products, or firmware versions are listed as affected in the available data. All installations of this firmware should be examined for exposure to this flaw.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact, and the EPSS score of less than 1% suggests that exploitation is unlikely to be widespread but still possible. The vulnerability is not listed in the CISA KEV catalog. Exploitation appears to require only local or remote access to the router’s configuration interface and does not require privileged credentials, making it relatively easy for an attacker who can reach the device network.
OpenCVE Enrichment