Impact
Netcore NR255‑V version 1.5.130703 contains a flaw in the handling of QoS bandwidth plan routes. The flaw allows authenticated users who possess broad roles to access read endpoints that expose live network telemetry. Consequently an attacker can obtain data that should be protected by the device’s privilege model, leading to exposure of network usage patterns and potentially sensitive internal information. The weakness is classified as CWE‑863, which represents insufficient constraint on the ability to read sensitive configuration or telemetry data.
Affected Systems
The affected device is the Netcore NR255‑V router, specifically release 1.5.130703. No other product versions or vendors are listed as impacted in the provided information.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, but the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not included in CISA’s Known Exploited Vulnerabilities catalog, so no widespread exploit activity is currently documented. The attack vector is inferred to require authenticated access with broad roles, meaning that while a broader user base can be impacted, the necessity of authentication lowers the risk compared to an unauthenticated flaw. The patch is therefore recommended but the urgency may be moderate, pending any emerging exploit reports.
OpenCVE Enrichment