Junglewise Threat Intelligence

CVE-2025-56015: GenieACS improper access control in NBI API

CVE-2025-56015 · Severity: high · CVSS 7.5 · Published 2026-04-07

Vendors: npm.

Executive brief

GenieACS is a TR-069 auto-configuration server used to manage and provision network devices. An unauthenticated attacker can access the NBI API endpoint to retrieve sensitive information including user credentials, file lists, and provisioning details without authentication, potentially leading to full system compromise and lateral movement in managed device networks.

Technical details

GenieACS contains an improper access control vulnerability (CWE-284) in the NBI API endpoint listening on port 7557. The vulnerability allows unauthenticated, network-accessible requests to retrieve sensitive information including user password hashes, salts, file lists, and provisioning configurations. Attack preconditions are minimal—only network access to port 7557 is required, with no authentication or user interaction necessary. An attacker can extract credential material and use it as a staging point for further attacks, including chaining with prototype pollution or code injection vulnerabilities. The vulnerability is documented as affecting version 1.2.13; patching status for later versions is uncertain and requires verification.

Affected products

  • GenieACS GenieACS 1.2.13

Timeline

  • 2026-04-07: disclosed: Published in OSV database
  • 2026-04-10: advisory: GitHub reviewed and published GHSA-2h6j-mhcp-9j9h

References

Related threats