CVE-2026-5756
Received Received - Intake
Unauthenticated Config File Modification in DRC COS Enables Data Exfiltration

Publication date: 2026-04-14

Last updated on: 2026-04-23

Assigner: CERT/CC

Description
Unauthenticated Configuration File Modification Vulnerability in DRC Central Office Services (COS) allows an attacker to modify the server's configuration file, potentially leading to mass data exfiltration, malicious traffic interception, or disruption of testing services.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-14
Last Modified
2026-04-23
Generated
2026-05-07
AI Q&A
2026-04-14
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
data_recognition_corporation drc_central_office_services *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is an Unauthenticated Configuration File Modification Vulnerability in DRC Central Office Services (COS). It allows an attacker to modify the server's configuration file without needing to authenticate. Such unauthorized modifications can lead to serious security issues.


How can this vulnerability impact me? :

The impact of this vulnerability includes potential mass data exfiltration, interception of malicious traffic, and disruption of testing services. This means attackers could steal large amounts of data, intercept or manipulate network traffic, or cause interruptions in critical testing operations.


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

The vulnerability allows an unauthenticated attacker to modify the server's configuration file, which could lead to mass data exfiltration and malicious traffic interception. Such unauthorized access and potential data breaches could negatively impact compliance with data protection regulations like GDPR and HIPAA, which require strict controls over personal and sensitive data to prevent unauthorized disclosure or alteration.

Specifically, the risk of mass data exfiltration may violate GDPR's requirements for data confidentiality and integrity, as well as HIPAA's mandates for protecting electronic protected health information (ePHI). Organizations using the affected DRC Central Office Services (COS) should consider this vulnerability a significant compliance risk.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart