Sceawere
Vulnerability Detail
CVE-2026-108578UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Neterbit NW-431F Information Disclosure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 4h ago
- Vendor
- Neterbit
- Product
- NW-431F
- Attack Type
- Information Disclosure
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in Neterbit NW-431F 20250715. Impacted is an unknown function of the file /sms.json of the component Embedded Web Server. Such manipulation leads to information disclosure. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-11T13:17:13.397Z",
"pubdate": "2026-10-11T13:17:13.397Z",
"executiveSummary": "A critical information disclosure vulnerability has been identified within the Neterbit NW-431F, version 20250715, specifically affecting the embedded web server component.\nThe vulnerability resides within the /sms.json file, allowing remote, unauthenticated attackers to exfiltrate sensitive data without requiring prior authorization.\nThe flaw manifests as an improper access control mechanism that exposes system-level information through a JSON-formatted interface.\nGiven the nature of the information disclosure, attackers could potentially gain insights into system configurations, user data, or operational parameters, facilitating further exploitation of the device.\nThe lack of vendor response exacerbates the risk, as no official patches are currently available to address the underlying security deficiency.\nOrganizations deploying the Neterbit NW-431F should assume the device is inherently susceptible to remote information harvesting and implement network-level segmentations to limit the attack surface.",
"technicalDetails": "The vulnerability is situated within the embedded web server of the Neterbit NW-431F (version 20250715), specifically targeting the /sms.json endpoint.\nThe root cause is an improper authorization check or a complete lack thereof when processing requests directed at the specified file path.\nThe /sms.json file serves as an interface for interacting with Short Message Service (SMS) data or related system configurations; however, the web server fails to validate the session state or privilege level of the requesting entity before returning the JSON payload.\nAn attacker can exploit this remotely by sending a standard HTTP GET request to the path /sms.json on the target device's web management interface.\nBecause the web server treats requests to this file as public or misconfigured as accessible, the application processes the request and serializes sensitive internal data into a JSON response, which is then transmitted back to the unauthorized client.\nThe attack flow is straightforward: 1) The attacker identifies a target Neterbit NW-431F device exposed to the network. 2) The attacker crafts an HTTP request targeting the /sms.json URI. 3) The embedded web server, failing to enforce security constraints, retrieves internal data (presumably cached or dynamic SMS-related records). 4) The server delivers the sensitive data in the clear via the HTTP response body.\nThis vulnerability is classified as an Information Disclosure, specifically falling under unauthorized data access. The post-exploitation impact includes the potential leakage of sensitive communication records, configuration details, or metadata that could be used for reconnaissance to facilitate more complex attacks.\nThe exposure is network-based, meaning any remote actor with connectivity to the management interface can execute this exploit. There is no requirement for specialized malware or complex chaining; a simple browser-based request or command-line tool like cURL is sufficient to trigger the disclosure.\nThe technical failure stems from the omission of authentication middleware or access control lists (ACLs) within the web server's routing logic for the /sms.json resource, leaving the data unprotected regardless of the device's administrative password settings."
}