Description
Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in mod_vpn_remote/plan.json, pptpd_user_show.cgi, pptp_client_config_show.cgi, and l2tpd_user_show.cgi. Attackers can leverage these components to obtain PPTP and L2TP VPN credentials.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Apply Patch
AI Analysis

Impact

Netcore NR255-V version 1.5.130703 contains a vulnerability that allows attackers to read VPN configuration files and CGI scripts that expose plain‑text PPTP and L2TP credentials. This results in a loss of confidentiality, giving attackers the ability to authenticate to VPN services and potentially pivot within the network. The weakness is a classic case of sensitive information exposure (CWE‑522).

Affected Systems

The issue affects routers running Netcore NR255‑V firmware 1.5.130703. The vulnerable components include mod_vpn_remote/plan.json, pptpd_user_show.cgi, pptp_client_config_show.cgi, and l2tpd_user_show.cgi, which are part of the router's VPN management interface.

Risk and Exploitability

The CVSS score of 7.1 indicates medium to high severity. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. However, an attacker with network access to the router could directly request the exposed CGI endpoints, making the attack relatively straightforward if the router is reachable from an untrusted network. Defenders should consider that exposure of credentials is a critical risk if the VPN is used for remote staff or trusted IoT devices.

Generated by OpenCVE AI on September 18, 2026 at 13:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the router firmware to a version where the CVE is resolved; if no patch exists, check the vendor’s website for a newer release.
  • Temporarily disable or restrict access to the PPTP and L2TP administrative interfaces (pptpd_user_show.cgi, pptp_client_config_show.cgi, l2tpd_user_show.cgi) until a patch is applied.
  • Implement network segmentation and firewall rules that limit management‑interface traffic to known administrators, and monitor logs for requests to the exposed endpoints.

Generated by OpenCVE AI on September 18, 2026 at 13:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Netcore
Netcore nr255-v
Vendors & Products Netcore
Netcore nr255-v

Tue, 15 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in mod_vpn_remote/plan.json, pptpd_user_show.cgi, pptp_client_config_show.cgi, and l2tpd_user_show.cgi. Attackers can leverage these components to obtain PPTP and L2TP VPN credentials.
Title Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via VPN Read Handlers
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T17:54:33.920Z

Reserved: 2026-08-19T21:47:08.936Z

Link: CVE-2026-76871

cve-icon Vulnrichment

Updated: 2026-09-21T17:54:30.430Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T22:17:02.200

Modified: 2026-09-21T18:17:10.683

Link: CVE-2026-76871

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T13:30:09Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials