Description
A vulnerability was identified in Neterbit NW-431F 20250715. Impacted is an unknown function of the file /sms.json of the component Embedded Web Server. Such manipulation leads to information disclosure. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-10-11
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

The vulnerability resides in an undocumented function handling the /sms.json endpoint of the embedded web server. An attacker can manipulate the request to extract sensitive information, leading to a disclosure of data that should remain private. The flaw does not require physical access and can be exploited over the network.

Affected Systems

Neterbit’s NW‑431F embedded networking appliance manufactured in the 20250715 release is affected. No other versions or products are listed as impacted.

Risk and Exploitability

The CVSS base score of 6.9 reflects moderate severity, with remote reachability and no local privilege elevation required. The EPSS score is unavailable but the vulnerability is not part of the CISA KEV catalog, indicating no confirmed large‑scale exploitation. Attackers could use the web interface from any reachable host, potentially revealing configuration or operational data.

Generated by OpenCVE AI on October 11, 2026 at 15:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict access to the embedded web server by limiting the network to trusted IP ranges or applying firewall rules that block external traffic to the /sms.json endpoint.
  • Apply any vendor‑issued firmware or software update that addresses the information‑disclosure flaw when it becomes available.
  • Implement robust authentication and authorization controls for the web interface, ensuring that only authorized users can access sensitive endpoints such as /sms.json.
  • Continuously monitor logs for unexpected or repeated access attempts to the /sms.json endpoint and alert on suspicious activities.

Generated by OpenCVE AI on October 11, 2026 at 15:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 13:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Neterbit NW-431F 20250715. Impacted is an unknown function of the file /sms.json of the component Embedded Web Server. Such manipulation leads to information disclosure. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Title Neterbit NW-431F Embedded Web Server sms.json information disclosure
First Time appeared Neterbit
Neterbit nw-431f
Weaknesses CWE-200
CWE-284
CPEs cpe:2.3:a:neterbit:nw-431f:*:*:*:*:*:*:*:*
Vendors & Products Neterbit
Neterbit nw-431f
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Neterbit Nw-431f
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-11T12:45:13.726Z

Reserved: 2026-10-10T15:51:14.627Z

Link: CVE-2026-108578

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:13.397

Modified: 2026-10-11T13:17:13.397

Link: CVE-2026-108578

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T15:45:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control