Sceawere

Vulnerability Detail

CVE-2026-52622UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Wellav WES API Information Disclosure

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
4h ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES280, and WES290 before 08-08-2023 allows a remote attacker to obtain sensitive information via the global API request wrapper function

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-25T13:17:14.787Z",
  "pubdate": "2026-09-25T13:17:14.787Z",
  "executiveSummary": "A critical information disclosure vulnerability exists in the global API request wrapper function within Wellav Technologies Co., Ltd WES series emergency broadcast terminals.\nThis vulnerability allows remote, unauthenticated attackers to bypass security controls and retrieve sensitive system data.\nAffected products include WES100, WES270, WES280, and WES290, specifically firmware versions released prior to 08-08-2023.\nThe vulnerability resides in the core API handling mechanism, which fails to properly sanitize or restrict access to requests processed through the global wrapper.\nThe risk implication is high, as an attacker can exfiltrate sensitive configuration data or internal operational parameters without requiring prior authentication.\nThe vulnerability is accessible over the network, making it reachable to any attacker with network connectivity to the affected terminal's management interface.",
  "technicalDetails": "The root cause of this vulnerability lies in an insecure implementation of the global API request wrapper function used across the WES series firmware architecture.\nThis wrapper function is responsible for intercepting and routing incoming API requests to the appropriate backend handlers. Analysis indicates that the function lacks sufficient authorization checks, allowing arbitrary API calls to be processed even when the requestor is unauthenticated.\nThe vulnerability manifests because the wrapper mechanism fails to validate the context of the incoming request against the current session state. Consequently, requests that should be restricted to authenticated administrative sessions are processed as legitimate requests regardless of the authentication token presence.\nThe attack flow proceeds as follows: 1) The attacker identifies the endpoint associated with the global API request wrapper. 2) The attacker crafts a malicious API request designed to trigger sensitive data retrieval. 3) The request is sent to the target WES terminal over the network. 4) The global API wrapper intercepts the request, fails to verify the authentication context, and passes the request to the underlying target service or function. 5) The underlying service executes the request and returns sensitive information, such as system configuration details or internal status data, directly to the attacker.\nThe affected component is the central request handling logic, which acts as an intermediary for all incoming management traffic. Because this component is globally scoped within the firmware, it effectively bypasses granular access controls implemented at the individual module or endpoint level.\nThis vulnerability impacts Wellav WES100, WES270, WES280, and WES290 devices running firmware versions older than 08-08-2023. There is no indication that specialized or administrative privileges are required to reach the wrapper, suggesting that the entry point is exposed by default.\nThe post-exploitation impact includes the potential for full system reconnaissance, credential harvesting if configuration files are returned, and the gathering of operational data that could facilitate further, more complex attacks against the infrastructure.\nThe flaw highlights a fundamental breakdown in the secure software development lifecycle regarding API gateway security and request validation."
}
CVE-2026-52622: Wellav WES API Information Disclosure (HIGH Severity, CVSS: 7.5) | Sceawere