Junglewise Threat Intelligence

CVE-2026-76857: Netcore NR255-V plaintext DDNS credential disclosure

CVE-2026-76857 · Severity: medium · CVSS 6.5 · Published 2026-09-15

Technologies: Netcore NR255-V. Vendors: Netcore.

Executive brief

The Netcore NR255-V is a wireless router used in home and small office networks. An authenticated attacker can extract plaintext DDNS account credentials from the router's web interface, leading to compromise of users' dynamic DNS accounts and potential redirection of traffic to attacker-controlled systems.

Technical details

The vulnerability is an insufficiently protected credentials disclosure (CWE-522) in the ddns_wan_list_show.cgi endpoint and related DDNSset_cgi, IGD_GetCgiHandler, and IGD_CgiCall components. An attacker with authentication to the router's web interface can access these CGI handlers to retrieve plaintext DDNS account credentials. The attack requires network reachability to the router's web interface and valid authentication credentials. Successful exploitation exposes sensitive DDNS account information, which can be used to take over DNS records pointing to the victim's network. No patch information is currently available.

Affected products

  • Netcore NR255-V 1.5.130703

Timeline

  • 2026-09-04: disclosed
  • 2026-09-15: advisory

References

Related threats