Impact
The vulnerability allows unauthenticated users to create, update, list, retrieve, and delete user accounts through REST API endpoints that lack proper authentication guards. This flaw grants attackers full control over account data, leading to potential confidentiality, integrity, and availability compromise for the affected system.
Affected Systems
The affected product is iot-ecology rust-iot-platform; the vulnerability exists in any deployment that includes commit 5df942ab or any state before the fix is applied. All REST API routes in this version are exposed without authentication checks, making every instance that has not updated to a patched release susceptible.
Risk and Exploitability
The CVSS score of 9.3 signals a very high severity condition. The EPSS score is not available, but the lack of built‑in authentication permits a remote attacker to reach and enumerate the vulnerable endpoints over the network. This vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote; no local credentials are required to exploit this flaw, making the attack trivial for anyone with network access to the API.
OpenCVE Enrichment