Impact
An attacker can obtain sensitive information by sending a remote request that includes a boardID and a revisionID component, allowing access to device identifiers that should be protected. The disclosed data may compromise the confidentiality of the device’s identity and could be leveraged for further targeted attacks. The weakness is a classic information‑disclosure flaw, as the system reveals information without proper authorization checks.
Affected Systems
The vulnerability affects Kerlink Wirnet iStation 868 devices running KerOS version 4.3.3_20200803132042. No other vendors or versions are listed in the advisory.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, while the EPSS score of less than 1% shows a currently low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is remote network access to the boardID/revisionID endpoint, requiring an attacker to reach the device over the network and issue a request that includes the boardID and revisionID parameters; no additional conditions are listed in the advisory.
OpenCVE Enrichment