Impact
The vulnerability resides in the ExposeApiAspect.beforeExposeApi method of dromara orion-visor. A hard‑coded credential is embedded in the source authentication token through remote manipulation. This bypasses the normal login mechanism, enabling unauthenticated access to the application’s API endpoints.
Affected Systems
All instances of dromara orion-visor versions up to and including 2.5.7 are affected. Deployments that have not upgraded beyond these releases expose the ExposeApiAspect feature and therefore carry the hard‑coded credential flaw.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity level. The EPSS score of < 1% indicates a very low but nonzero probability of exploitation, suggesting that the vulnerability is unlikely to be widely targeted. However, publicly available exploit code means the issue is operationally demonstrable. The vulnerability is not listed in CISA’s KEV catalog, but the remote nature of the attack vector and the lack of a vendor response increase the urgency for defensive action.
OpenCVE Enrichment