Description
Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the mod_qos_bandwidth plan.json handling within filter_conns_dump_cgi.c and IGD_CgiCall.c. Authenticated users with broad roles can access these QoS read routes to obtain live network telemetry beyond their intended privilege level.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Patch
AI Analysis

Impact

Netcore NR255‑V version 1.5.130703 contains a flaw in the handling of QoS bandwidth plan routes. The flaw allows authenticated users who possess broad roles to access read endpoints that expose live network telemetry. Consequently an attacker can obtain data that should be protected by the device’s privilege model, leading to exposure of network usage patterns and potentially sensitive internal information. The weakness is classified as CWE‑863, which represents insufficient constraint on the ability to read sensitive configuration or telemetry data.

Affected Systems

The affected device is the Netcore NR255‑V router, specifically release 1.5.130703. No other product versions or vendors are listed as impacted in the provided information.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, but the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not included in CISA’s Known Exploited Vulnerabilities catalog, so no widespread exploit activity is currently documented. The attack vector is inferred to require authenticated access with broad roles, meaning that while a broader user base can be impacted, the necessity of authentication lowers the risk compared to an unauthenticated flaw. The patch is therefore recommended but the urgency may be moderate, pending any emerging exploit reports.

Generated by OpenCVE AI on September 16, 2026 at 20:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑supplied firmware update or patch that addresses the QoS bandwidth plan JSON handling flaw in Netcore NR255‑V 1.5.130703.
  • Revoke or restrict the roles of authenticated users who can call QoS read endpoints, limiting access to only those essential for normal operation.
  • Configure firewalls or network segmentation to block external or internal access to the QoS bandwidth plan routes until a patch is applied.

Generated by OpenCVE AI on September 16, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the mod_qos_bandwidth plan.json handling within filter_conns_dump_cgi.c and IGD_CgiCall.c. Authenticated users with broad roles can access these QoS read routes to obtain live network telemetry beyond their intended privilege level.
Title Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via QoS Bandwidth Plan Routes
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-16T19:03:41.443Z

Reserved: 2026-08-19T21:47:08.936Z

Link: CVE-2026-76863

cve-icon Vulnrichment

Updated: 2026-09-16T19:03:28.780Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T22:17:00.823

Modified: 2026-09-16T20:21:01.047

Link: CVE-2026-76863

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T20:30:06Z

Weaknesses