Executive brief
The Netcore NR255-V is a wireless router used in enterprise and residential networks. A vulnerability in its captive-portal authentication component exposes user credentials stored in the device, allowing attackers who access the web interface to retrieve login information for network users. This compromises the security of authenticated network access and could enable unauthorized access to the network.
Technical details
The vulnerability is a sensitive information disclosure flaw (CWE-522) in the l7_web_auth_user_show.cgi CGI script, which handles captive-portal user credential management. An authenticated attacker can query this web component to retrieve captive-portal user credentials in cleartext or weakly protected form. The attack vector is network-based and requires login credentials to the router's web interface. An attacker with administrative or authenticated access can extract credentials for all network users, compromising confidentiality of network authentication. No patch information is currently available in the advisory.
Affected products
- Netcore NR255-V 1.5.130703
Timeline
- 2026-09-04: disclosed
- 2026-09-15: advisory