Impact
The vulnerability resides in the l2tpd_config_show.c, ipsec_show_cgi.c, and mod_vpn_remote/plan.json read handlers of Netcore NR255-V 1.5.130703. An unauthenticated attacker who can access the l2tpd_config_show.cgi endpoint can obtain stored IPsec pre‑shared keys and RSA key material. Disclosure of these secrets compromises the confidentiality of encrypted traffic and may enable full network compromise. This defect is categorized as CWE-522: Sensitive Data Exposure.
Affected Systems
Netcore's NR255-V router firmware version 1.5.130703 is affected. No other platforms or firmware versions are reported as vulnerable according to the available CNA information.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate severity level. The EPSS score of < 1% suggests that exploitation is rare at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. Likely attack requires network reach to the device's web interface and sending a request CGI script. No authentication or privilege described.
OpenCVE Enrichment