CVE-2026-52622

An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES280, and WES290 before 08-08-2023 allows a remote attacker to obtain sensitive information via the global API request wrapper function

  • Published Sep 25, 2026
  • CVSS 7.5 high
  • 0.3% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

CVE-2026-52622 at the National Vulnerability Database