Impact
Netcore NR255‑V version 1.5.130703 exposes sensitive information through its audit endpoints, specifically those handled by l7_web_auth_log_dump_c and mod_dispatch_auth/plan.json. The flaw allows an attacker to request audit data and retrieve other users’ session identifiers and browsing history across different sessions. The weakness is classified as CWE‑359, a sensitive information disclosure.
Affected Systems
The vulnerability affects Netcore NR255‑V devices running firmware version 1.5.130703. No other versions or vendors are listed as impacted in the current advisory.
Risk and Exploitability
The CVSS score of 7.1 indicates significant impact, while the EPSS score of < 1% reflects a low probability of widespread exploitation. It is inferred that the audit endpoints are likely accessible via the router’s web interface, so an adversary with network access could, in theory, issue HTTP requests to these endpoints to extract the disclosed data. It is also inferred that no authentication requirement is needed to access these endpoints, as the description does not mention authentication.
OpenCVE Enrichment