Impact
The flaw exists in the EIP_Com_FileList.aspx component of NewType WebEIP and allows an attacker to bypass authentication mechanisms, enabling unauthorized users to access sensitive URL endpoints. Because the vulnerability is rooted in improper authentication (CWE-287), compromised credentials or lack of proper session validation can expose internal file listings and potentially other protected resources. The official description notes the exploit is publicly available and can be triggered remotely, underscoring the risk to any exposed WebEIP interfaces.
Affected Systems
NewType WebEIP versions up to 3.0 are affected. The precise product is named WebEIP, and the issue is tied to the file /EIP_Com_FileList.aspx. No additional version or patch information is provided, but all installations of WebEIP 1.x through 3.0 that have not applied a vendor‑issued fix remain vulnerable.
Risk and Exploitability
The CVSS score of 6.9 places this vulnerability in the moderate severity range. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog, indicating no known large‑scale exploitation yet. The attack vector is inferred as remote, given the description that the exploit can be launched from outside the internal network. Without a patch, attackers may bypass authentication and potentially gain unauthorized access to resources served by EIP_Com_FileList.aspx.
OpenCVE Enrichment