Impact
WireGuard Portal (wg-portal) is a web‑based configuration tool for managing WireGuard servers. An authenticated WebSocket endpoint /api/v0/ws is intended to provide per‑user statistics. However, in versions 2.2.0 through prior to 2.3.0, the code forwards all TrafficDelta events for both peer and interface statistics without performing per‑user authorization checks. As a result, a low‑privilege user can subscribe to the WebSocket and receive bytes received/transmitted data, peer public keys, interface names and other traffic metrics that belong to other users. This leakage exposes the volume and identity of network traffic, allowing an attacker to map active connections and infer usage patterns. The vulnerability is an instance of missing per‑user authorization, classified as CWE‑285. It does not expose any cryptographic material or raw tunnel traffic.
Affected Systems
The defect is specific to the h44z wg‑portal product, versions 2.2.0 through any 2.2.x release before the fix. The vulnerability was addressed in the 2.3.0 release, as documented in the GitHub commit and release notes. All installations running an affected version with the WebSocket statistics feature enabled are susceptible. Protection requires upgrading to v2.3.0 or later or disabling the statistics endpoint for non‑administrator accounts.
Risk and Exploitability
The publicly available CVSS metric assigns a 4.3 score, indicating low severity. EPSS is reported at < 1 %, suggesting a very low chance of exploitation. The vulnerability is not listed in the CISA KEV catalog, reinforcing its lower profile. The attack requires an authenticated session with a non‑administrator account, so the threat surface is limited to users with legitimate portal access. While the information disclosed is non‑critical data, such as traffic volumes and peer identifiers, it can still aid reconnaissance or privacy‑breach objectives. Because the issue is not remote code execution and occurs only within authenticated users, an organization can realistically mitigate risk through patching or endpoint restriction.
OpenCVE Enrichment