Impact
This vulnerability arises from incorrect access control in the /uci/get/ endpoint of Novus AirGate 4G firmware. An attacker can send a crafted POST request without authentication to leak administrator credentials stored on the device. The disclosed administrator credentials represent a significant confidentiality breach; the CVE description does not explicitly state the attacker’s ability to control device functions or the network, but possession of such credentials could be leveraged for further attacks. The impact is therefore credential disclosure rather than inferred control.
Affected Systems
Novus AirGate 4G firmware 1.1.16 is affected. No other versions or products are listed as impacted.
Risk and Exploitability
The lack of authentication for this endpoint means that unauthenticated remote attackers can readily retrieve credentials. The EPSS score of 0.0002 and the fact that it is not listed in the CISA KEV catalog suggest a relatively low probability of exploitation, but the high CVSS score of 9.1 indicates significant impact if exploited. The inherent nature of the flaw still warrants attention, especially in environments where the endpoint is exposed to the public Internet.
OpenCVE Enrichment