CVE-2026-52622: Infoleak
Published Sep 25, 2026
·Updated
An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES280, and WES290 before 08-08-2023 allows a remote attacker to obtain sensitive information via the global API request wrapper function
Affected Software
1 affected component
Wellav Technologies WES Emergency Broadcast Terminal WES100, WES270, WES280, and WES290<08-08-2023
Event History
Sep 25, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which devices are affected?
The affected products are Wellav WES Emergency Broadcast Terminal models WES100, WES270, WES280, and WES290 running versions before 08-08-2023.
2
Does exploitation require authentication or user interaction?
No. The supplied vector indicates network-based exploitation with no privileges required and no user interaction.
3
What is exposed if the issue is exploited?
A remote attacker can obtain sensitive information through the global API request wrapper function. The provided data indicates high confidentiality impact, with no stated integrity impact.