Impact
A buffer overflow occurs in the update URLs component of Kerlink KerOS running on the Wirnet iStation 868. When triggered, the flaw allows a remote attacker to read memory and exfiltrate sensitive information, but does not provide direct code execution or denial of service.
Affected Systems
Devices running Kerlink Wirnet iStation 868 with KerOS version 4.3.3 (build 20200803132042) are affected. No additional version ranges are specified.
Risk and Exploitability
The CVSS score of 3.5 indicates low severity, and the EPSS score of less than 1% reflects a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote via the device’s update mechanism, which an attacker could exploit if allowed network access to the update URLs.
OpenCVE Enrichment