Impact
Netcore NR255-V version 1.5.130703 contains a vulnerability that allows attackers to read VPN configuration files and CGI scripts that expose plain‑text PPTP and L2TP credentials. This results in a loss of confidentiality, giving attackers the ability to authenticate to VPN services and potentially pivot within the network. The weakness is a classic case of sensitive information exposure (CWE‑522).
Affected Systems
The issue affects routers running Netcore NR255‑V firmware 1.5.130703. The vulnerable components include mod_vpn_remote/plan.json, pptpd_user_show.cgi, pptp_client_config_show.cgi, and l2tpd_user_show.cgi, which are part of the router's VPN management interface.
Risk and Exploitability
The CVSS score of 7.1 indicates medium to high severity. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. However, an attacker with network access to the router could directly request the exposed CGI endpoints, making the attack relatively straightforward if the router is reachable from an untrusted network. Defenders should consider that exposure of credentials is a critical risk if the VPN is used for remote staff or trusted IoT devices.
OpenCVE Enrichment