Description
An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via a boardID and revisionID components
Published: 2026-07-16
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker can obtain sensitive information by sending a remote request that includes a boardID and a revisionID component, allowing access to device identifiers that should be protected. The disclosed data may compromise the confidentiality of the device’s identity and could be leveraged for further targeted attacks. The weakness is a classic information‑disclosure flaw, as the system reveals information without proper authorization checks.

Affected Systems

The vulnerability affects Kerlink Wirnet iStation 868 devices running KerOS version 4.3.3_20200803132042. No other vendors or versions are listed in the advisory.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity, while the EPSS score of less than 1% shows a currently low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is remote network access to the boardID/revisionID endpoint, requiring an attacker to reach the device over the network and issue a request that includes the boardID and revisionID parameters; no additional conditions are listed in the advisory.

Generated by OpenCVE AI on August 5, 2026 at 02:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict network access to the boardID/revisionID endpoint to trusted IP ranges or VPN only.
  • Check the Kerlink website or contact Kerlink support for a firmware update that addresses this information‑disclosure issue.
  • Monitor device logs for unexpected boardID or revisionID queries and respond promptly if suspicious activity is detected.

Generated by OpenCVE AI on August 5, 2026 at 02:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via Board ID and Revision ID in Kerlink Wirnet iStation 868
Weaknesses CWE-200

Tue, 04 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Information Disclosure via BoardID and RevisionID Parameters in Kerlink Wirnet iStation 868
Weaknesses CWE-200

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Kerlink
Kerlink wirnet Istation 868 Keros
Vendors & Products Kerlink
Kerlink wirnet Istation 868 Keros

Fri, 31 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Information Disclosure via BoardID and RevisionID Parameters in Kerlink Wirnet iStation 868
Weaknesses CWE-200

Wed, 29 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Kerlink Wirnet iStation boardID/RevisionID information disclosure vulnerability
Weaknesses CWE-200

Sat, 25 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Kerlink Wirnet iStation boardID/RevisionID information disclosure vulnerability
Weaknesses CWE-200

Thu, 16 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via a boardID and revisionID components
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AC:L/AV:A/A:N/C:L/I:N/PR:N/S:U/UI:N'}


Subscriptions

Kerlink Wirnet Istation 868 Keros
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-17T13:34:16.641Z

Reserved: 2024-04-12T00:00:00.000Z

Link: CVE-2024-32385

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:30:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor