When supplied with non-existent course IDs, the router returned JSON data instead of a standard 404 response. This discrepancy enables attackers to distinguish between valid and invalid course identifiers, facilitating user enumeration or reconnaissance. Versions affected: 5.0 to 5.0.2 Versions fixed: 5.0.3