CyberRota Analysis
AI-GeneratedNext Terminal is vulnerable due to inadequate enforcement of per-asset authorization checks on its portal ping and wake-on-LAN endpoints. This flaw allows any authenticated user to access and manipulate assets they should not have permission to, potentially exposing sensitive asset information and enabling unauthorized wake-on-LAN actions. Organizations using Next Terminal should prioritize addressing this vulnerability to prevent unauthorized access and potential exploitation of their network assets.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Next Terminal fails to enforce per-asset authorization checks on the portal ping and wake-on-LAN endpoints, allowing any authenticated user to probe and wake assets they are not granted access to. Attackers can call these endpoints with arbitrary asset identifiers to retrieve asset information including display names, reachability status, connection timing, and network addresses, or trigger wake-on-LAN packets on unauthorized assets.