CVE-2026-92256: Netcore NR255-V 1.5.130703 IPsec PSK and RSA Key Disclosure via l2tpd_config_show.cgi Read Handlers
Published Sep 15, 2026
·Updated
NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l2tpdconfigshowcgi.c, ipsecshowcgi.c, and modvpnremote/plan.json read handlers. Attackers can query l2tpdconfigshow.cgi to expose stored IPsec PSK and RSA key material.
Affected Software
1 affected component
Netcore NR255-V=1.5.130703
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NR255-Vto a version that resolves this vulnerability.Fixed in 1.5.130703
Event History
Sep 15, 2026
CVE Published
via MITRE·09:58 PM
Data Sourced
via MITRE·09:58 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to retrieve the exposed key material?
The vulnerability requires low-privileged access. It is remotely reachable and does not require user interaction.
2
Which secrets may be exposed?
Queries to l2tpd_config_show.cgi can expose stored IPsec pre-shared keys and RSA key material.
3
Which components are implicated beyond l2tpd_config_show.cgi?
The affected read handlers are in l2tpd_config_show_cgi.c, ipsec_show_cgi.c, and mod_vpn_remote/plan.json.