Executive brief
The Netcore NR255-V is a home/small office router that manages network quality-of-service (QoS) settings to prioritize traffic. Authenticated users with limited roles can bypass access controls to view real-time network traffic data (telemetry) they should not have permission to see, potentially exposing network usage patterns and device activity to unauthorized accounts.
Technical details
This is a privilege escalation and authorization bypass vulnerability (CWE-863) in the mod_qos_bandwidth component, specifically in plan.json handling within filter_conns_dump_cgi.c and IGD_CgiCall.c. Authenticated users with broad roles can access QoS read routes that should be restricted by permission level, allowing them to retrieve live network telemetry beyond their intended access scope. The vulnerability requires prior authentication to exploit; network accessibility is not a constraint since it runs on the router management interface. An attacker with a low-privilege authenticated account can retrieve network monitoring data. CVSS v4.0 score is 5.3 (vector: AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N). Patch status is not documented in available references.
Affected products
- Netcore NR255-V 1.5.130703
Timeline
- 2026-09-04: disclosed
- 2026-09-15: advisory