Impact
A vulnerability in Tranquil IT Systems' WAPT Server versions earlier than 2.6.1.17813 allows a remote unauthenticated attacker to bypass authentication controls. By sending a specially crafted packet, the server issues a valid session token for the targeted account, effectively hijacking that account’s session. This results in the attacker gaining all privileges associated with the victim account. Based on the description, it is inferred that the attacker can perform actions as the victim without needing to obtain or guess credentials. The flaw reflects a typical CWE‑288 weakness involving improper validation of authentication packets.
Affected Systems
The affected system is the WAPT Server from Tranquil IT Systems. Any installation running a version prior to 2.6.1.17813 is vulnerable. Organizations should verify their server version and assess whether they remain exposed.
Risk and Exploitability
The CVSS score of 10 indicates critical severity, with no authentication required and a remote attack vector. EPSS data is not available, and the issue is not listed in CISA KEV; however, the nature of the bypass strongly suggests ample motivation for attackers who can discover the packet. The likely attack vector is over the network to the WAPT Server’s management or API endpoints. Because the vulnerability is accessible remotely and requires no pre‑existing credentials, the risk to exposed deployments is high, warranting immediate remediation to prevent credential theft and potential lateral movement.
OpenCVE Enrichment