Junglewise Threat Intelligence

CVE-2026-76871: Netcore NR255-V credential disclosure in VPN components

CVE-2026-76871 · Severity: medium · CVSS 6.5 · Published 2026-09-15

Technologies: Netcore NR255-V. Vendors: Netcore.

Executive brief

The Netcore NR255-V router is a networking device used to manage VPN connections for remote access. A vulnerability allows authenticated attackers to directly access and extract PPTP and L2TP VPN credentials (usernames and passwords) through publicly readable web interface endpoints. An attacker with network access and login credentials could obtain all stored VPN user credentials, compromising the security of remote access and potentially enabling lateral movement into corporate networks.

Technical details

This is a sensitive information disclosure vulnerability (CWE-522) affecting multiple CGI scripts and configuration endpoints in Netcore NR255-V version 1.5.130703. The vulnerable components (mod_vpn_remote/plan.json, pptpd_user_show.cgi, pptp_client_config_show.cgi, and l2tpd_user_show.cgi) fail to properly protect VPN credentials, exposing PPTP and L2TP user accounts and passwords. The attack requires network access to the router's web interface and valid authentication credentials. An attacker with router access can retrieve plaintext or insufficiently obfuscated VPN credentials used for remote access. No patch status is publicly documented; users should contact Netcore for firmware updates.

Affected products

  • Netcore NR255-V 1.5.130703

Timeline

  • 2026-09-04: disclosed
  • 2026-09-15: advisory

References

Related threats