Description
Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the SNMP update mechanism.
Published: 2026-07-16
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Directory traversal in Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to read arbitrary files on the device by exploiting the SNMP update mechanism. This flaw can expose system configuration files and other sensitive data, compromising confidentiality. The weakness is identified as CWE‑22, indicating that improper validation of path input leads to unrestricted file access.

Affected Systems

The vulnerability is present in the Kerlink Wirnet iStation 868 running KerOS firmware version 4.3.3_20200803132042. Devices with this firmware that expose the SNMP update interface to untrusted networks are susceptible. No other versions or products were enumerated in the CVE data.

Risk and Exploitability

The CVSS base score of 7.3 reflects a moderate to high risk due to remote exploitation and the potential for significant data disclosure. The EPSS indicates a very low probability of exploitation (<1 %), suggesting that, while possible in theory, real-world attacks are unlikely to be observed yet. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to reach the SNMP update endpoint, which is typically available on the local network; from the internet, it would need to traverse multiple network layers. The impact is confined to confidentiality, with no indication that the flaw could lead to code execution or denial of service.

Generated by OpenCVE AI on August 1, 2026 at 08:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to a patched firmware version once available from Kerlink
  • Restrict SNMP update access to trusted IPs or networks using firewall or ACLs
  • Disable SNMP update functionality if not required for your deployment

Generated by OpenCVE AI on August 1, 2026 at 08:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Kerlink
Kerlink wirnet Istation 868 Keros
Vendors & Products Kerlink
Kerlink wirnet Istation 868 Keros

Sat, 01 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Directory Traversal via SNMP Update in Kerlink Wirnet iStation 868 KerOS

Tue, 28 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Directory Traversal via SNMP Update in Kerlink Wirnet iStation 868 KerOS

Sat, 25 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Kerlink Wirnet iStation Directory Traversal via SNMP Update

Wed, 22 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Kerlink Wirnet iStation Directory Traversal via SNMP Update

Fri, 17 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the SNMP update mechanism.
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AC:L/AV:A/A:N/C:H/I:H/PR:N/S:U/UI:R'}


Subscriptions

Kerlink Wirnet Istation 868 Keros
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-17T13:41:06.510Z

Reserved: 2024-04-12T00:00:00.000Z

Link: CVE-2024-32386

cve-icon Vulnrichment

Updated: 2026-07-17T13:41:00.972Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:36:22Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')