Junglewise Threat Intelligence

CVE-2023-24215: NOVUS AirGate 4G incorrect access control in /uci/get/ endpoint

CVE-2023-24215 · Severity: info · CVSS 8.1 · Published 2026-05-18

Executive brief

A security flaw in the NOVUS AirGate 4G cellular gateway allows unauthorized individuals to steal administrator passwords. This device is typically used to provide internet connectivity and remote access for industrial equipment. If exploited, an attacker could take full control of the gateway, potentially disrupting operations or gaining access to the internal network it protects.

Technical details

An incorrect access control vulnerability exists in the /uci/get/ endpoint of NOVUS AirGate 4G firmware version v1.1.16. The endpoint fails to enforce proper authentication or authorization checks, allowing a remote, unauthenticated attacker to send a specially crafted POST request to retrieve sensitive configuration data, including administrator credentials. Successful exploitation grants the attacker full administrative access to the device's web interface and configuration, leading to a complete compromise of the gateway's integrity and confidentiality. At the time of reporting, the vulnerability is confirmed in version 1.1.16.

Affected products

  • NOVUS AirGate 4G v1.1.16

Timeline

  • 2026-05-18: advisory: NVD publication date

References