Impact
The Netcore NR255-V version 1.5.130703 contains a missing access control flaw in the l7_web_auth_user_show.cgi script that allows an attacker to query the component and retrieve captive‑portal user credentials, compromising the confidentiality of network access for users connected through the portal and is classified as CWE‑522, data exposure.
Affected Systems
Netcore NR255-V, version 1.5.130703 is affected by this vulnerability. No other versions or products are listed as impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity of the information disclosure. The EPSS score is less than 1 %, suggesting a very low probability of exploitation at this time, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is a remote HTTP request to the l7_web_auth_user_show.cgi endpoint, which, if exposed publicly, could be used by an attacker to harvest captive‑portal credentials.
OpenCVE Enrichment