Impact
The vulnerability is a cryptographic timing side‑channel that lets an attacker with no prior authentication forge valid credentials and bypass the back‑end authentication and authorization mechanisms. By exploiting this flaw the attacker can impersonate a legitimate client and gain full access to the system configuration, enabling modification, reset, or unauthorized alteration of critical parameters.
Affected Systems
The affected product is OMICRON electronics GmbH StationGuard firmware before version 4.10. No other versions or vendors are listed in the current data.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity, and the absence of an EPSS rating indicates that no recent public exploitation data is available. The flaw is listed as not being part of the CISA KEV catalog, so it is not known to be actively exploited in the wild. Based on the description it is inferred that the attack vector is remote, as an unauthenticated attacker can send authentication requests to the backend and observe timing differences to build valid credentials.
OpenCVE Enrichment