Executive brief
The Netcore NR255-V is a wireless router used in home and small office networks. An authenticated attacker can extract plaintext DDNS account credentials from the router's web interface, leading to compromise of users' dynamic DNS accounts and potential redirection of traffic to attacker-controlled systems.
Technical details
The vulnerability is an insufficiently protected credentials disclosure (CWE-522) in the ddns_wan_list_show.cgi endpoint and related DDNSset_cgi, IGD_GetCgiHandler, and IGD_CgiCall components. An attacker with authentication to the router's web interface can access these CGI handlers to retrieve plaintext DDNS account credentials. The attack requires network reachability to the router's web interface and valid authentication credentials. Successful exploitation exposes sensitive DDNS account information, which can be used to take over DNS records pointing to the victim's network. No patch information is currently available.
Affected products
- Netcore NR255-V 1.5.130703
Timeline
- 2026-09-04: disclosed
- 2026-09-15: advisory