If the company doesn't have a security bug bounty program, then no, you shouldn't expect a monetary reward. Most of the time you'll get a "thank you" email, sometimes not even that.
Also, some companies have been known to threaten/press charges against people that report vulnerabilities to them. Be careful when you report stuff that you stumble upon.
> Is there any issue of legality here if I were to request compensation for the reproduction method?
Don't go there, just don't. Be satisfied that you managed to get the right people to listen, hope that they fix it, and just forget about it.