Impact
An issue in Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 permits a remote attacker to obtain sensitive information through the community string component. The vulnerability is an information exposure flaw (CWE‑200) combined with the use of hard‑coded credentials (CWE‑798), allowing an attacker to learn confidential data that the device processes or stores. The disclosed data can compromise the confidentiality of the device and the network it supports, potentially revealing configuration details, network topology, or other sensitive information.
Affected Systems
Affected products are Kerlink Wirnet iStation 868 appliances running KerOS firmware version 4.3.3_20200803132042. No other vendors or versions are reported to be impacted.
Risk and Exploitability
The CVSS score of 5.7 reflects a moderate impact, and the EPSS score of less than 1 % indicates a low probability of exploitation at the time of this analysis. The vulnerability is not listed in CISA KEV catalog. The likely attack vector is remote; an attacker can supply a crafted community string or credential to trigger the data leak, assuming network access to the device. No direct exploitation conditions such as privilege escalation are described, but the exposure remains a risk to data confidentiality.
OpenCVE Enrichment