Kerlink KerOS
- <= 4.3.3
A vulnerability in the SNMP implementation of Kerlink Wirnet iStation 868 running KerOS versions through 4.3.3 has been identified. The issue arises from the use of a predictable SNMP community string, which is derived from hardware-dependent information. This predictability allows remote attackers to obtain sensitive information by recovering the community string with a low number of brute-force attempts. The vulnerability is compounded by an additional information disclosure issue that can be exploited to aid in the recovery of the community string.
Exploitation of this vulnerability could lead to unauthorized access to SNMP-managed resources, allowing for potential manipulation or monitoring of those resources. The predictable community string could be brute-forced, leading to information disclosure.
Users are advised to upgrade to the latest version of KerOS 6, as KerOS 4 and 5 are no longer supported. Instructions for updating can be found in the Kerlink IoT Solutions catalog.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.