Impact
Netcore NR255-V routers running version 1.5.130703 contain a flaw in the user_pass_show.cgi component that allows disclosure of stored credentials. The vulnerability is triggered when a low‑privilege user interacts with the ui_config_2.xml configuration file and the auxiliary misc.js script. When exploited, an attacker can retrieve the router’s administrative user and password, compromising the confidentiality of the device’s management interface.
Affected Systems
The affected device is the Netcore NR255-V router with firmware build 1.5.130703. No other products or versions are listed as affected in the available data. Inspect all instances of this firmware for exposure.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact, and the EPSS score of less than 1% suggests that exploitation is unlikely to be widespread but still possible. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires only local access to the router’s configuration interface and does not need privileged credentials, making it relatively easy for an attacker who can reach the device network.
OpenCVE Enrichment