CVE-2026-52622
Received Received - Intake

Information Disclosure in Wellav WES Emergency Broadcast Terminal

Vulnerability report for CVE-2026-52622, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: MITRE

Description

An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES280, and WES290 before 08-08-2023 allows a remote attacker to obtain sensitive information via the global API request wrapper function

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-25
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wellav_technologies wes_emergency_broadcast_terminal to 2023-08-08 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Wellav Technologies' WES Emergency Broadcast Terminal devices (models WES100, WES270, WES280, WES290) running firmware before 08-08-2023. It allows a remote attacker to access sensitive information through a flaw in the global API request wrapper function.

Impact Analysis

An attacker could remotely exploit this to steal sensitive data from affected devices. This may include confidential information processed or stored by the emergency broadcast terminals, potentially leading to privacy breaches or unauthorized access to system data.

Compliance Impact

This vulnerability could lead to non-compliance with data protection regulations like GDPR or HIPAA if sensitive personal or health data is exposed. Organizations using these devices may face legal penalties, reputational damage, and increased scrutiny for failing to protect regulated data.

Mitigation Strategies

Update the Wellav WES Emergency Broadcast Terminal devices (WES100, WES270, WES280, WES290) to firmware version 08-08-2023 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-52622. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart