CVE-2026-76871: Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via VPN Read Handlers
Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in modvpnremote/plan.json, pptpdusershow.cgi, pptpclientconfigshow.cgi, and l2tpdusershow.cgi. Attackers can leverage these components to obtain PPTP and L2TP VPN credentials.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Netcore NR255-Vto a version that resolves this vulnerability.Fixed in 1.5.130703 - Compensating control
Mitigate exposure while patching by restricting VPN credential-relevant endpoints (e.g., handlers in mod_vpn_remote/plan.json, pptpd_user_show.cgi, pptp_client_config_show.cgi, and l2tpd_user_show.cgi) to trusted management clients via network/ACL controls.
Event History
Frequently Asked Questions
What level of access does an attacker need to retrieve the VPN credentials?
The CVSS vector indicates that an attacker needs low-level privileges (PR:L). Exploitation does not require user interaction and can be performed over the network.
Which credentials could be exposed?
The affected VPN read handlers can disclose PPTP and L2TP VPN credentials.
How can I determine whether this issue applies to my device?
This issue is reported for Netcore NR255-V running version 1.5.130703. The listed affected components are mod_vpn_remote/plan.json, pptpd_user_show.cgi, pptp_client_config_show.cgi, and l2tpd_user_show.cgi.