Impact
The flaw in WifiBurada permits an attacker to bypass authentication, enabling unauthorized access to private personal information. It arises from insufficient protection of credentials, which is categorized as a credential access weakness and an authentication bypass. The vulnerability can potentially be exploited by anyone who can interact with the service, resulting in a confidentiality breach of sensitive data. The vendor has not provided a public fix and the issue remains present through version 21052026.
Affected Systems
Digital Operations Services Inc. WifiBurada, all versions up to and including the release with build identifier 21052026.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, but the EPSS score is not available, so the current probability of exploitation remains unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting no documented widespread exploitation yet. Based on the description, the likely attack vector is an unauthenticated or low‑privileged attempt to authenticate via an OTP bypass or credential leakage. The flaw allows an attacker to obtain personal data because the authentication mechanism does not enforce proper credential validation.
OpenCVE Enrichment