CVE-2026-76855
Received Received - Intake

Sensitive Information Disclosure in Netcore NR255-V

Vulnerability report for CVE-2026-76855, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: VulnCheck

Description

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the audit endpoints handled by l7_web_auth_log_dump_cgi.c, audit_get_cgi.c, and mod_dispatch_auth/plan.json. Attackers can query these audit components to obtain other users' session and browsing history data across sessions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
netcore nr255-v 1.5.130703

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-359 The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a sensitive information disclosure issue in Netcore NR255-V version 1.5.130703. It allows attackers to access other users' session and browsing history data by querying specific audit endpoints.

Detection Guidance

Check for unauthorized access to audit endpoints like l7_web_auth_log_dump_cgi.c, audit_get_cgi.c, or mod_dispatch_auth/plan.json. Monitor logs for unusual queries to these paths. Use network scanning tools to detect requests targeting these endpoints.

Impact Analysis

Attackers could exploit this to steal sensitive data like session tokens or browsing history, leading to privacy breaches, unauthorized account access, or exposure of confidential information.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized data exposure. GDPR requires protecting personal data, while HIPAA mandates safeguarding health information. Exploitation could result in legal penalties and reputational damage.

Mitigation Strategies

Disable or restrict access to the vulnerable audit endpoints. Update to a patched version of Netcore NR255-V if available. Implement network-level controls to block external access to these components.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76855. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart