Description
An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the community string component.
Published: 2026-07-16
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An issue in Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 permits a remote attacker to obtain sensitive information through the community string component. The vulnerability is an information exposure flaw (CWE‑200) combined with the use of hard‑coded credentials (CWE‑798), allowing an attacker to learn confidential data that the device processes or stores. The disclosed data can compromise the confidentiality of the device and the network it supports, potentially revealing configuration details, network topology, or other sensitive information.

Affected Systems

Affected products are Kerlink Wirnet iStation 868 appliances running KerOS firmware version 4.3.3_20200803132042. No other vendors or versions are reported to be impacted.

Risk and Exploitability

The CVSS score of 5.7 reflects a moderate impact, and the EPSS score of less than 1 % indicates a low probability of exploitation at the time of this analysis. The vulnerability is not listed in CISA KEV catalog. The likely attack vector is remote; an attacker can supply a crafted community string or credential to trigger the data leak, assuming network access to the device. No direct exploitation conditions such as privilege escalation are described, but the exposure remains a risk to data confidentiality.

Generated by OpenCVE AI on July 31, 2026 at 02:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Kerlink KerOS firmware to the latest version that contains the fix, if available
  • Restrict external network access to the device by applying firewall rules or VLAN segmentation so that only trusted hosts can reach the community string interface
  • Disable or change the default community string and hard‑coded credentials, ensuring they are not exposed to untrusted networks
  • Monitor device logs for suspicious attempts to read the community string and investigate any unauthorized access

Generated by OpenCVE AI on July 31, 2026 at 02:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Kerlink
Kerlink wirnet Istation 868 Keros
Vendors & Products Kerlink
Kerlink wirnet Istation 868 Keros

Fri, 31 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Community String Information Disclosure in Kerlink Wirnet iStation 868 KerOS v4.3.3

Tue, 28 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Community String in Kerlink Wirnet iStation Firmware

Wed, 22 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Community String in Kerlink Wirnet iStation Firmware

Fri, 17 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-798
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the community string component.
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AC:L/AV:A/A:N/C:H/I:N/PR:N/S:U/UI:R'}


Subscriptions

Kerlink Wirnet Istation 868 Keros
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-17T13:42:03.575Z

Reserved: 2024-04-12T00:00:00.000Z

Link: CVE-2024-32387

cve-icon Vulnrichment

Updated: 2026-07-17T13:41:57.737Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:36:21Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-798

    Use of Hard-coded Credentials