Summary by c3L0Mu1d3R
A Broken Function Level Authorization (BFLA) vulnerability was identified in the DIRS (FCC) platform, where an authenticated API endpoint intended solely for submitting “Critical Need of Help” requests also accepts unauthorized GET requests that return all historical submissions.
As a result, low-privileged users can retrieve bulk sensitive and personally identifiable information (PII) belonging to other organizations and individuals, including emergency details and operational metadata. This exposure enables mass data disclosure, increases the risk of targeted phishing and social-engineering attacks during disaster scenarios, and impacts a FCC system used for emergency and communications infrastructure response.