Executive brief
The Netcore NR255-V router exposes stored VPN credentials (IPsec pre-shared keys and RSA encryption keys) through web-based configuration handlers. An attacker with network access can retrieve cryptographic material used to secure VPN connections, enabling unauthorized access to encrypted VPN tunnels or facilitating man-in-the-middle attacks.
Technical details
A sensitive information disclosure vulnerability exists in the l2tpd_config_show_cgi.c, ipsec_show_cgi.c, and mod_vpn_remote/plan.json read handlers within NR255-V 1.5.130703. The vulnerability allows authenticated attackers to query the l2tpd_config_show.cgi endpoint to retrieve IPsec pre-shared keys (PSK) and RSA key material in plaintext or insufficiently protected form. The attack requires network connectivity and valid authentication credentials. Successful exploitation exposes cryptographic secrets used for VPN tunnel establishment, allowing compromise of encrypted communications. A patch status has not been disclosed.
Affected products
- Netcore NR255-V 1.5.130703
Timeline
- 2026-09-04: disclosed
- 2026-09-15: advisory