Executive brief
WifiBurada, a digital operations service, contains a security flaw that fails to properly protect user credentials and private information. An attacker could exploit this to bypass authentication mechanisms and gain unauthorized access to the system. This could lead to the exposure of sensitive customer data and unauthorized use of the service.
Technical details
WifiBurada is vulnerable to an authentication bypass stemming from insufficiently protected credentials (CWE-522) and the exposure of private personal information to unauthorized actors (CWE-359). The vulnerability allows a network-based attacker with low privileges to bypass security controls and access sensitive data. According to the advisory, the vendor was notified but did not respond, and no official patch has been confirmed. The CVSS 3.1 score of 7.1 reflects high confidentiality impact but limited integrity and availability impact.
Affected products
- Digital Operations Services Inc. WifiBurada through 21052026
Timeline
- 2026-05-21: advisory: NVD and TR-CERT published the vulnerability details.
- 2026-05-21: disclosed: Public disclosure occurred after the vendor failed to respond to early contact.