Kerlink Wirnet iStation 868 KerOS Predictable SNMP Community String Information Disclosure Vulnerability

Vulnerability

A vulnerability in the SNMP implementation of Kerlink Wirnet iStation 868 running KerOS versions through 4.3.3 has been identified. The issue arises from the use of a predictable SNMP community string, which is derived from hardware-dependent information. This predictability allows remote attackers to obtain sensitive information by recovering the community string with a low number of brute-force attempts. The vulnerability is compounded by an additional information disclosure issue that can be exploited to aid in the recovery of the community string.

Impact

Exploitation of this vulnerability could lead to unauthorized access to SNMP-managed resources, allowing for potential manipulation or monitoring of those resources. The predictable community string could be brute-forced, leading to information disclosure.

Remediation

Users are advised to upgrade to the latest version of KerOS 6, as KerOS 4 and 5 are no longer supported. Instructions for updating can be found in the Kerlink IoT Solutions catalog.

Added: Jul 16, 2026, 11:25 PM
Updated: Jul 16, 2026, 11:25 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.9
remediation
0.0
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.