Information Disclosure Vulnerability in Neterbit NW-431F Embedded Web Server
CVE-2026-108578

6.9MEDIUM

Key Information:

Vendor

Neterbit

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108578?

A vulnerability exists in the Neterbit NW-431F embedded web server that allows an attacker to remotely access sensitive information by exploiting an insecure function in the /sms.json file. This manipulation could lead to unauthorized data exposure, compromising user privacy while revealing sensitive configurations of the device. Despite attempts to communicate the issue to the vendor, no response has been recorded, raising concerns over the urgency and impact of this security flaw.

Affected Version(s)

NW-431F 20250715

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

libssl (VulDB User)
VulDB CNA Team
.