Description
Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the update URLs component.
Published: 2026-07-16
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer overflow occurs in the update URLs component of Kerlink KerOS running on the Wirnet iStation 868. When triggered, the flaw allows a remote attacker to read memory and exfiltrate sensitive information, but does not provide direct code execution or denial of service.

Affected Systems

Devices running Kerlink Wirnet iStation 868 with KerOS version 4.3.3 (build 20200803132042) are affected. No additional version ranges are specified.

Risk and Exploitability

The CVSS score of 3.5 indicates low severity, and the EPSS score of less than 1% reflects a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote via the device’s update mechanism, which an attacker could exploit if allowed network access to the update URLs.

Generated by OpenCVE AI on August 1, 2026 at 08:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device to a KerOS version that resolves the buffer‑overflow issue.
  • Restrict or block inbound traffic to the update URLs component using firewalls or ACLs to prevent external access.
  • Monitor update‑related logs for anomalous activity that could indicate attempts to exploit the buffer overflow.

Generated by OpenCVE AI on August 1, 2026 at 08:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Kerlink
Kerlink wirnet Istation 868 Keros
Vendors & Products Kerlink
Kerlink wirnet Istation 868 Keros

Sat, 01 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow Enables Remote Information Disclosure via Update URLs Component

Tue, 28 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow Enables Remote Information Disclosure via Update URLs Component

Sun, 26 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Kerlink Wirnet iStation 868 KerOS Enables Remote Information Disclosure

Wed, 22 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Kerlink Wirnet iStation 868 KerOS Enables Remote Information Disclosure

Fri, 17 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the update URLs component.
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AC:L/AV:A/A:N/C:L/I:N/PR:N/S:U/UI:R'}


Subscriptions

Kerlink Wirnet Istation 868 Keros
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-17T13:40:20.550Z

Reserved: 2024-04-12T00:00:00.000Z

Link: CVE-2024-32389

cve-icon Vulnrichment

Updated: 2026-07-17T13:40:16.373Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:36:19Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')