Impact
Netcore NR255‑V version 1.5.130703 exposes sensitive information through its audit endpoints, specifically those handled by l7_web_auth_log_dump_c and mod_dispatch_auth/plan.json. The flaw allows an attacker to request audit data and retrieve other users’ session identifiers and browsing history across different sessions. The weakness is classified as CWE‑359, a sensitive information disclosure.
Affected Systems
The vulnerability affects Netcore NR255‑V devices running firmware version 1.5.130703. No other versions or vendors are listed as impacted in the current advisory.
Risk and Exploitability
The CVSS score of 7.1 indicates significant impact, while the EPSS score of < 1% reflects a low probability of widespread exploitation. The vulnerability is not listed in the CISA KE remote: the audit endpoints are accessible via the router’s web interface, so an adversary with network access can issue HTTP requests to these endpoints to extract the disclosed data. No authentication requirement is described.
OpenCVE Enrichment