Katsunari Yoshioka

Pesquisador deYokohama National University
#874de 53,635
232.4CVSS total
Vulnerabilidades · 34
Média
21
Alta
7
Crítica
6
PT-2025-3848
7.5
2025-01-15
Nec · Aterm Gb1200Pe · CVE-2025-0355
**Name of the Vulnerable Software and Affected Versions** NEC Corporation Aterm WG2600HS versions 1.7.2 and earlier NEC Corporation Aterm WF1200CRS versions 1.6.0 and earlier NEC Corporation Aterm WG1200CRS versions 1.5.0 and earlier NEC Corporation Aterm GB1200PE versions 1.3.0 and earlier NEC Corporation Aterm WG2600HP4 versions 1.4.2 and earlier NEC Corporation Aterm WG2600HM4 versions 1.4.2 and earlier NEC Corporation Aterm WG2600HS2 versions 1.3.2 and earlier NEC Corporation Aterm WX3000HP versions 2.4.2 and earlier NEC Corporation Aterm WX4200D5 versions 1.2.4 and earlier **Description** The issue allows an attacker to obtain a Wi-Fi password via the network due to missing authentication for a critical function. **Recommendations** For NEC Corporation Aterm WG2600HS versions 1.7.2 and earlier, update to a version later than 1.7.2. For NEC Corporation Aterm WF1200CRS versions 1.6.0 and earlier, update to a version later than 1.6.0. For NEC Corporation Aterm WG1200CRS versions 1.5.0 and earlier, update to a version later than 1.5.0. For NEC Corporation Aterm GB1200PE versions 1.3.0 and earlier, update to a version later than 1.3.0. For NEC Corporation Aterm WG2600HP4 versions 1.4.2 and earlier, update to a version later than 1.4.2. For NEC Corporation Aterm WG2600HM4 versions 1.4.2 and earlier, update to a version later than 1.4.2. For NEC Corporation Aterm WG2600HS2 versions 1.3.2 and earlier, update to a version later than 1.3.2. For NEC Corporation Aterm WX3000HP versions 2.4.2 and earlier, update to a version later than 2.4.2. For NEC Corporation Aterm WX4200D5 versions 1.2.4 and earlier, update to a version later than 1.2.4.
PT-2025-3847
4.8
2025-01-15
Nec · Aterm Wx3000Hp · CVE-2025-0354
**Nome do Software Vulnerável e Versões Afetadas** NEC Corporation Aterm WG2600HS versões 1.7.2 e anteriores NEC Corporation Aterm WG2600HP4 versões 1.4.2 e anteriores NEC Corporation Aterm WG2600HM4 versões 1.4.2 e anteriores NEC Corporation Aterm WG2600HS2 versões 1.3.2 e anteriores NEC Corporation Aterm WX3000HP versões 2.4.2 e anteriores NEC Corporation Aterm WX4200D5 versões 1.2.4 e anteriores **Descrição** Um problema de cross-site scripting permite que um atacante injete um script arbitrário via rede. Isso pode potencialmente levar a ações não autorizadas no sistema afetado. **Recomendações** Para o NEC Corporation Aterm WG2600HS versões 1.7.2 e anteriores, atualize para uma versão superior à 1.7.2 para resolver o problema. Para o NEC Corporation Aterm WG2600HP4 versões 1.4.2 e anteriores, atualize para uma versão superior à 1.4.2 para resolver o problema. Para o NEC Corporation Aterm WG2600HM4 versões 1.4.2 e anteriores, atualize para uma versão superior à 1.4.2 para resolver o problema. Para o NEC Corporation Aterm WG2600HS2 versões 1.3.2 e anteriores, atualize para uma versão superior à 1.3.2 para resolver o problema. Para o NEC Corporation Aterm WX3000HP versões 2.4.2 e anteriores, atualize para uma versão superior à 2.4.2 para resolver o problema. Para o NEC Corporation Aterm WX4200D5 versões 1.2.4 e anteriores, atualize para uma versão superior à 1.2.4 para resolver o problema.
PT-2023-21090
9.8
2023-05-23
T&D · Wdr-3 · CVE-2023-27388
**Name of the Vulnerable Software and Affected Versions** T&D Corporation data logger products versions TR-71W/72W all firmware versions T&D Corporation data logger products versions RTR-5W all firmware versions T&D Corporation data logger products versions WDR-7 all firmware versions T&D Corporation data logger products versions WDR-3 all firmware versions T&D Corporation data logger products versions WS-2 all firmware versions ESPEC MIC CORP. data logger products versions RT-12N/RS-12N all firmware versions ESPEC MIC CORP. data logger products versions RT-22BN all firmware versions ESPEC MIC CORP. data logger products versions TEU-12N all firmware versions **Description** An improper authentication issue in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login to the product as a registered user. **Recommendations** For T&D Corporation data logger products versions TR-71W/72W all firmware versions, consider disabling remote access until a patch is available. For T&D Corporation data logger products versions RTR-5W all firmware versions, restrict access to the product to minimize the risk of exploitation. For T&D Corporation data logger products versions WDR-7 all firmware versions, avoid using default or weak passwords for registered users. For T&D Corporation data logger products versions WDR-3 all firmware versions, limit the number of login attempts to prevent brute-force attacks. For T&D Corporation data logger products versions WS-2 all firmware versions, implement additional authentication mechanisms, such as two-factor authentication. For ESPEC MIC CORP. data logger products versions RT-12N/RS-12N all firmware versions, consider changing default passwords and restricting access to the product. For ESPEC MIC CORP. data logger products versions RT-22BN all firmware versions, disable any unnecessary features or services that could be exploited. For ESPEC MIC CORP. data logger products versions TEU-12N all firmware versions, monitor user activity and login attempts to detect potential exploitation.