CVE-2026-76863
Received Received - Intake

Netcore NR255-V QoS Bandwidth Plan Information Disclosure

Vulnerability report for CVE-2026-76863, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: VulnCheck

Description

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the mod_qos_bandwidth plan.json handling within filter_conns_dump_cgi.c and IGD_CgiCall.c. Authenticated users with broad roles can access these QoS read routes to obtain live network telemetry beyond their intended privilege level.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
netcore nr255-v 1.5.130703

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a sensitive information disclosure issue in Netcore NR255-V version 1.5.130703. It occurs in the mod_qos_bandwidth plan.json handling within specific files. Authenticated users with broad roles can access QoS read routes to obtain live network telemetry beyond their intended privilege level.

Detection Guidance

To detect this vulnerability, check for unauthorized access to QoS read routes in Netcore NR255-V version 1.5.130703. Monitor network traffic for requests to mod_qos_bandwidth plan.json endpoints. Review logs for unusual access patterns by authenticated users with broad roles.

Impact Analysis

An attacker with authenticated access could exploit this to view sensitive network telemetry data they are not authorized to see. This could include real-time network performance metrics or other confidential information.

Compliance Impact

This vulnerability allows authenticated users with broad roles to access sensitive network telemetry data beyond their intended privilege level. This could lead to unauthorized disclosure of personal or sensitive information, which may violate compliance requirements under regulations like GDPR (data protection) and HIPAA (health information privacy).

Mitigation Strategies

Update Netcore NR255-V to the latest version that patches the sensitive information disclosure vulnerability in mod_qos_bandwidth plan.json handling. Restrict authenticated user roles to the minimum required privileges to prevent unauthorized access to QoS read routes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76863. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart