Impact
Next Terminal fails to enforce per‑asset authorization on its portal ping and wake‑on‑LAN (WOL) endpoints. Because any authenticated user can call these endpoints with arbitrary asset identifiers, an attacker can probe assets that the user is not granted access to. The response reveals asset display names, reachability status, connection timing, and network addresses, and allows the sending of wake‑on‑LAN packets to unauthorized assets. This breach exposes confidential asset information and provides a covert method to wake devices without proper authorization.
Affected Systems
The vulnerable product is Next Terminal, a web‑based terminal management platform. The CNA identifies the affected vendor/product as next‑terminal:next‑terminal. No specific version information is supplied, so it is inferred that all releases prior to the fix are likely affected until a definitive version is announced by the vendor.
Risk and Exploitability
Risk assessment reflects a moderate severity CVSS score of 5.3. Because the EPSS score is not publicly available and the vulnerability is not listed in CISA’s KEV catalog, the likelihood of exploitation is uncertain. The likely attack vector is authenticated access to the portal endpoints, meaning that an attacker needs valid credentials or a compromised account to leverage the flaw. Once authenticated, the attacker can exploit the flaw to discover sensitive asset details or trigger unsolicited wake‑on‑LAN traffic, potentially disrupting services.
OpenCVE Enrichment