Junglewise Threat Intelligence

CVE-2026-13211: genua genucenter information disclosure in SNMP configuration interface

CVE-2026-13211 · Severity: medium · CVSS 4.3 · Published 2026-07-01

Executive brief

genucenter, a central management station for IT security solutions, contains a flaw that exposes sensitive network credentials. Users with administrative or service-level access can view SNMP authentication and encryption keys in plain text within the web interface's source code. An attacker with these credentials could potentially monitor or control managed network devices, compromising the security of the entire infrastructure.

Technical details

An information disclosure vulnerability (CWE-201) exists in the genucenter web interface due to the unnecessary inclusion of sensitive data in HTTP responses. When a user with 'Service' or 'Admin' privileges accesses specific SNMP configuration endpoints, the application embeds SNMP authentication and encryption keys in plain text within the HTML source code. This allows an authenticated attacker to extract these keys using standard browser developer tools or automated scripts. The vulnerability is present in versions up to 8.0p10 and is fixed in version 8.0p11 and 8.6 or later. An attacker with these keys could gain unauthorized access to monitor or manage network devices via SNMP.

Affected products

  • genua genucenter 8.0 through 8.0p10

Timeline

  • 2026-07-01: advisory: NVD published the CVE record.
  • 2026-07-01: disclosed: SBA Research published the technical advisory.

References