Executive brief
The Netcore NR255-V is a wireless router used to provide internet connectivity in small offices and homes. A vulnerability in the router's web interface allows low-privilege attackers to extract stored Wi-Fi and admin credentials from the device without elevated access. An attacker who gains initial access to the router could retrieve these credentials to move laterally within the network or maintain persistent access.
Technical details
This is a sensitive information disclosure vulnerability (CWE-522) in the user_pass_show.cgi component of the Netcore NR255-V router firmware version 1.5.130703. The vulnerable code path involves ui_config_2.xml and misc.js, which insufficiently protect stored credentials. The attack requires network access to the router's web interface and low-privilege authentication; an authenticated attacker can request the user_pass_show.cgi endpoint to retrieve plaintext or weakly protected credentials. The vulnerability allows disclosure of router admin passwords and wireless network credentials. Patch status is unknown at this time.
Affected products
- Netcore NR255-V 1.5.130703
Timeline
- 2026-09-04: disclosed
- 2026-09-15: advisory