Impact
The Netcore NR255-V router firmware version 1.5.130703 has a vulnerability in the l7_web_auth_user_show.cgi CGI script that allows an attacker to query the endpoint and retrieve captive-portal user credentials. The flaw is a missing access control that leads to an exposure of sensitive authentication data, thereby compromising the confidentiality of network access for users that connect through the captive portal. This flaw is classified as CWE-522, Data Exposure.
Affected Systems
Netcore NR255-V router firmware version 1.5.130703 is affected. No other versions or products are listed as impacted in the advisory.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity for an information‑disclosure flaw. The EPSS score of less than 1 % suggests the probability of exploitation is currently very low, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a remote HTTP request to the l7_web_auth_user_show.cgi endpoint, which, if publicly accessible, could allow an adversary to harvest captive‑portal credentials.
OpenCVE Enrichment