---
id: CVE-2026-52622
title: >-
  An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast
  Terminal WES100, WES270, WES280, and WES290 before 08-08-2023 allows a remote
  attacker to obtain sensitive information via the global API request wrapper
  function
summary: >-
  An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast
  Terminal WES100, WES270, WES280, and WES290 before 08-08-2023 allows a remote
  attacker to obtain sensitive information via the global API request wrapper
  function
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T13:17:14.787'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-52622'
references:
  - url: >-
      https://jl-zhenlaixiaowei.blog.csdn.net/article/details/166365472?spm=1001.2014.3001.5502
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T13:08:53.497Z'
---

## Overview

An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES280, and WES290 before 08-08-2023 allows a remote attacker to obtain sensitive information via the global API request wrapper function

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
