OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-52622

HIGH · CVSS 7.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Wellav Technologies' WES Emergency Broadcast Terminals (models WES100, WES270, WES280, and WES290) prior to August 8, 2023, are vulnerable to a remote information disclosure flaw due to inadequate protections in the global API request wrapper function. This vulnerability could allow attackers to access sensitive information, posing significant risks to the confidentiality of emergency communications. Organizations utilizing these terminals should prioritize patching to mitigate potential exploitation.

CVE
CVE-2026-52622
Severity
HIGH
CVSS
7.5
EPSS
0.30%

Original NVD Description

An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES280, and WES290 before 08-08-2023 allows a remote attacker to obtain sensitive information via the global API request wrapper function