Impact
The vulnerability is a lack of proper authorization checks in the MatchEngine::update_lob function of the internal limit order book cache handler. An attacker who can trigger this function from an external interface can manipulate the enforcement of the behavioral workflow, effectively changing how orders are handled. This can lead to incorrect order processing, potential manipulation of order data, and disruption of the trading engine. The weakness is reflected in CWE-840 and CWE-841, indicating missing or improper authorization steps.
Affected Systems
The affected product is WonderTrader up to and including version 0.9.9. All installations of this trading software running those versions are vulnerable. No additional product variants or component versions are listed beyond the generic WonderTrader identifier.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not provided, so the likelihood of exploitation in the wild cannot be quantified from the data. This vulnerability is not listed in the CISA KEV catalog. Remote exploitation is explicitly noted in the description, suggesting that the attack vector is through the system’s external interfaces. Based on the description, it is inferred that an attacker could gain remote control over the order book’s behavioral workflow and exploit this to disrupt service or modify order data.
OpenCVE Enrichment