CVE-2026-76859: Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via user_pass_show.cgi
Published Sep 15, 2026
·Updated
Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the userpassshow.cgi component. Low-privilege attackers can exploit this flaw via uiconfig2.xml and misc.js to disclose router credentials.
Affected Software
1 affected component
Netcore NR255-V=1.5.130703
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Netcore NR255-V user_pass_show.cgito a version that resolves this vulnerability.Fixed in 1.5.130703Patch Sensitive Information Disclosure via user_pass_show.cgi
Event History
Sep 15, 2026
CVE Published
via MITRE·09:57 PM
Data Sourced
via MITRE·09:57 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
An attacker needs low-privilege access to the router. The vulnerability is remotely reachable and does not require user interaction.
2
What information can be exposed?
The flaw can disclose router credentials through the user_pass_show.cgi component, using ui_config_2.xml and misc.js.