Impact
The vulnerability is a missing authentication flaw that allows unauthenticated users to access a critical management API in the Baylan Smart Meter Management Application. The flaw enables an attacker to bypass authentication checks and execute privileged operations via the API, representing a severe authorization weakness (CWE-306).
Affected Systems
Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) before version 1.1.10.142 is affected. Users of earlier versions are at risk if the management API is exposed to untrusted networks.
Risk and Exploitability
The CVSS score of 9.8 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated, remote request to the exposed API, assuming the system is reachable over a network. An attacker could gain unauthorized control over meter management functions without needing any credentials.
OpenCVE Enrichment