CWE-522

CWE-522 · 6 records · 6 with a public proof-of-concept

Records the NVD classes under CWE-522, highest CVSS first.

  1. MEDIUM 6.5CVE-2026-92256public PoC

    NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l2tpd_config_show_cgi.c, ipsec_show_cgi.c, and mod_vpn_remote/plan.json read handlers. Attackers can query l2tpd_config_show.cgi to expose stored IPsec PSK and RSA key mate

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 6.5CVE-2026-76871public PoC

    Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in mod_vpn_remote/plan.json, pptpd_user_show.cgi, pptp_client_config_show.cgi, and l2tpd_user_show.cgi. Attackers can leverage these components to obtain PPTP and L2TP

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 6.5CVE-2026-76859public PoC

    Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the user_pass_show.cgi component. Low-privilege attackers can exploit this flaw via ui_config_2.xml and misc.js to disclose router credentials.

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 6.5CVE-2026-76857public PoC

    Netcore NR255-V firmware version 1.5.130703 contains a sensitive information disclosure vulnerability in the ddns_wan_list_show.cgi endpoint and related DDNSset_cgi, IGD_GetCgiHandler, and IGD_CgiCall components. Attackers who reach this CGI handler can obtain

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 6.5CVE-2026-76854public PoC

    Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l7_web_auth_user_show.cgi related to captive-portal credential handling. Attackers can query this component to obtain captive-portal user credentials, compromising

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 6.5CVE-2026-71260public PoC

    ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (esphome/components/web_server/web_server.cpp), a text entity configured with mode: password (TEXT_MODE_PASSWORD) has its JSON "state" field corre

    AI risk analysis on Exploit-DB.ai →