Junglewise Threat Intelligence

CVE-2026-76855: Netcore NR255-V sensitive information disclosure in audit endpoints

CVE-2026-76855 · Severity: medium · CVSS 6.5 · Published 2026-09-15

Technologies: Netcore NR255-V. Vendors: Netcore.

Executive brief

The Netcore NR255-V is a network router used in enterprise environments to manage connectivity and security. A flaw in its audit logging endpoints allows authenticated attackers to retrieve other users' session tokens and browsing history, potentially exposing confidential web activity and enabling account hijacking or further lateral movement within the organization.

Technical details

This is a sensitive information disclosure vulnerability (CWE-359) in the audit endpoint handlers (l7_web_auth_log_dump_cgi.c, audit_get_cgi.c, and mod_dispatch_auth/plan.json) within Netcore NR255-V version 1.5.130703. The vulnerability requires an authenticated user to query the audit components over the network; no special privilege level or user interaction is required beyond authentication. By exploiting this flaw, an attacker can cross-reference audit logs to extract session identifiers and browsing records of other users across multiple sessions. No patch information is currently public, though this is likely to be addressed by the vendor in a future firmware release.

Affected products

  • Netcore NR255-V 1.5.130703

Timeline

  • 2026-09-04: disclosed
  • 2026-09-15: advisory

References

Related threats