CVE-2026-76859
Received Received - Intake

Netcore NR255-V Credential Disclosure via ui_config_2.xml

Vulnerability report for CVE-2026-76859, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: VulnCheck

Description

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the user_pass_show.cgi component. Low-privilege attackers can exploit this flaw via ui_config_2.xml and misc.js to disclose router credentials.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
netcore nr255-v 1.5.130703

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Netcore NR255-V version 1.5.130703 has a sensitive information disclosure vulnerability in the user_pass_show.cgi component. Attackers with low privileges can exploit this flaw by accessing ui_config_2.xml and misc.js to retrieve router credentials.

Impact Analysis

An attacker could gain access to router credentials, potentially allowing them to intercept network traffic, modify settings, or launch further attacks within the network. This could lead to unauthorized access to connected devices or sensitive data.

Mitigation Strategies

Update the Netcore NR255-V router to the latest firmware version that addresses this vulnerability. If an update is not available, consider replacing the device with a supported model. Restrict access to the router's web interface from untrusted networks and change all default credentials to strong, unique passwords.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76859. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart