Impact
The vulnerability in Kener allows an unauthenticated attacker to read hidden or inactive monitor data. By sending requests to dashboard API endpoints that lack proper visibility filters, an attacker can retrieve the monitor’s name, description, status, uptime history and latency. This is a classic information disclosure weakness (CWE-200), exposing sensitive operational data to anyone who can reach the API.
Affected Systems
The affected product is Kener, version 4.0.0 up to and including 4.1.5. These releases are hosted by the vendor rajnandan1 and provide the dashboard API that is susceptible to the data disclosure flaw.
Risk and Exploitability
The flaw carries a CVSS score of 6.9, indicating a medium‑to‑high risk level. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a remote, unauthenticated network request to the open API endpoints. Once the attacker supplies a known or guessed monitor tag, the missing visibility checks allow the disclosure, making the issue exploitable without any privilege escalation or additional configuration.
OpenCVE Enrichment