CVE-2026-76859

Summary

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the user_pass_show.cgi component. Low-privilege attackers can exploit this flaw via ui_config_2.xml and misc.js to disclose router credentials.

Affected Software

VendorProductVersion RangeStatus
NetcoreNR255-V1.5.130703affected

Weaknesses

  • CWE-522: Insufficiently Protected Credentials

References