Impact
The vulnerability exists in the ExposeApiAspect.beforeExposeApi method of dromara orion-visor, where a hard‑coded credential is embedded in the code. An attacker can invoke this functionality remotely and obtain default authentication tokens, bypassing proper login controls. This leads to unauthorized access, potentially enabling full compromise of the system, including data read, modification, and service disruption. The weakness is a classic credential storage flaw, identified by CWE‑259 and CWE‑798.
Affected Systems
The flaw affects dromara's Orion Visor application up to and including version 2.5.7. Current deployments of Orion Visor that have not applied a later patch are vulnerable. The software is distributed under the open‑source dromara project and is typically accessed through its exposed API endpoints.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity risk, and the publicly available exploit code confirms that the issue can be leveraged remotely without special privileges. Because the EPSS score is not available, the current exploitation likelihood is unclear, but the existence of a public exploit and the lack of response from the vendor reduce the window for defensive action. The vulnerability is not yet listed in CISA’s KEV catalog, so it is not classified as a known widely‑used exploit, yet the potential for widespread abuse remains if the default token remains undisclosed.
OpenCVE Enrichment