Impact
The vulnerability resides in an undocumented function handling the /sms.json endpoint of the embedded web server. An attacker can manipulate the request to extract sensitive information, leading to a disclosure of data that should remain private. The flaw does not require physical access and can be exploited over the network.
Affected Systems
Neterbit’s NW‑431F embedded networking appliance manufactured in the 20250715 release is affected. No other versions or products are listed as impacted.
Risk and Exploitability
The CVSS base score of 6.9 reflects moderate severity, with remote reachability and no local privilege elevation required. The EPSS score is unavailable but the vulnerability is not part of the CISA KEV catalog, indicating no confirmed large‑scale exploitation. Attackers could use the web interface from any reachable host, potentially revealing configuration or operational data.
OpenCVE Enrichment