Impact
Directory traversal in Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to read arbitrary files on the device by exploiting the SNMP update mechanism. This flaw can expose system configuration files and other sensitive data, compromising confidentiality. The weakness is identified as CWE‑22, indicating that improper validation of path input leads to unrestricted file access.
Affected Systems
The vulnerability is present in the Kerlink Wirnet iStation 868 running KerOS firmware version 4.3.3_20200803132042. Devices with this firmware that expose the SNMP update interface to untrusted networks are susceptible. No other versions or products were enumerated in the CVE data.
Risk and Exploitability
The CVSS base score of 7.3 reflects a moderate to high risk due to remote exploitation and the potential for significant data disclosure. The EPSS indicates a very low probability of exploitation (<1 %), suggesting that, while possible in theory, real-world attacks are unlikely to be observed yet. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to reach the SNMP update endpoint, which is typically available on the local network; from the internet, it would need to traverse multiple network layers. The impact is confined to confidentiality, with no indication that the flaw could lead to code execution or denial of service.
OpenCVE Enrichment