Impact
The vulnerability resides in the l2tpd_config_show.c, ipsec_show_cgi.c, and mod_vpn_remote/plan.json read handlers of Netcore NR255-V 1.5.130703. An unauthenticated attacker who can access the l2tpd_config_show.cgi endpoint can obtain stored IPsec pre‑shared keys and RSA key material. Disclosure of these secrets compromises the confidentiality of encrypted traffic and may enable full network compromise. This defect is categorized as CWE-522: Sensitive Data Exposure.
Affected Systems
Netcore's NR255-V router firmware version 1.5.130703 is affected. No other platforms or firmware versions are reported as vulnerable according to the available CNA information.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level. The EPSS score of < 1% suggests that exploitation is rare at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network reach to the device's web interface, where an attacker can send a request to the l2tpd_config_show.cgi script without authentication. No authentication or privilege is required beyond physical or network access to the router's administrative interface.
OpenCVE Enrichment