Impact
This vulnerability arises from incorrect access control in the /uci/get/ endpoint of Novus AirGate 4G firmware. An attacker can send a crafted POST request without authentication to leak administrator credentials stored on the device. The resulting exposure of privileged credentials permits full control over subsequent device functions and potentially the network associated with it.
Affected Systems
Novus AirGate 4G firmware 1.1.16 is affected. No other versions or products are listed as impacted.
Risk and Exploitability
The lack of authentication for this endpoint means that unauthenticated remote attackers can readily retrieve credentials. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the inherent nature of the flaw suggests a high likelihood of exploitation, especially in environments where the endpoint is exposed to the public Internet. The CVSS score is not provided in the data, yet the impact level implies a severe threat.
OpenCVE Enrichment