Description
Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in mod_vpn_remote/plan.json, pptpd_user_show.cgi, pptp_client_config_show.cgi, and l2tpd_user_show.cgi. Attackers can leverage these components to obtain PPTP and L2TP VPN credentials.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Apply Patch
AI Analysis

Impact

Netcore NR255-V version 1.5.130703 contains a vulnerability that allows attackers to read VPN configuration files and CGI scripts that expose plain‑text PPTP and L2TP credentials. This results in a loss of confidentiality, giving attackers the ability to authenticate to VPN services and potentially pivot within the network. The weakness is a classic case of sensitive information exposure (CWE‑522).

Affected Systems

The issue affects routers running Netcore NR255‑V firmware 1.5.130703. The vulnerable components include mod_vpn_remote/plan.json, pptpd_user_show.cgi, pptp_client_config_show.cgi, and l2tpd_user_show.cgi, which are part of the router's VPN management interface.

Risk and Exploitability

The CVSS score of 7.1 indicates medium to high severity. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. However, an attacker with network access to the router could directly request the exposed CGI endpoints, making the attack relatively straightforward if the router is reachable from an untrusted network. Defenders should consider that exposure of credentials is a critical risk if the VPN is used for remote staff or trusted IoT devices.

Generated by OpenCVE AI on September 16, 2026 at 20:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router firmware to a version where the CVE is resolved; if no patch exists, check the vendor’s website for a newer release.
  • Temporarily disable or restrict access to the PPTP and L2TP administrative interfaces (pptpd_user_show.cgi, pptp_client_config_show.cgi, l2tpd_user_show.cgi) until a patch is applied.
  • Implement network segmentation and firewall rules that limit management‑interface traffic to known administrators, and monitor logs for requests to the exposed endpoints.

Generated by OpenCVE AI on September 16, 2026 at 20:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in mod_vpn_remote/plan.json, pptpd_user_show.cgi, pptp_client_config_show.cgi, and l2tpd_user_show.cgi. Attackers can leverage these components to obtain PPTP and L2TP VPN credentials.
Title Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via VPN Read Handlers
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T21:58:01.852Z

Reserved: 2026-08-19T21:47:08.936Z

Link: CVE-2026-76871

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T22:17:02.200

Modified: 2026-09-16T19:47:01.197

Link: CVE-2026-76871

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T20:30:06Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials