Junnosuke Kushibiki

Researcher fromYokohama National University
#6517of 53,633
41.7Total CVSS
Vulnerabilities · 6
Medium
4
High
1
Critical
1
PT-2023-21090
9.8
2023-05-23
T&D · Wdr-3 · CVE-2023-27388
**Name of the Vulnerable Software and Affected Versions** T&D Corporation data logger products versions TR-71W/72W all firmware versions T&D Corporation data logger products versions RTR-5W all firmware versions T&D Corporation data logger products versions WDR-7 all firmware versions T&D Corporation data logger products versions WDR-3 all firmware versions T&D Corporation data logger products versions WS-2 all firmware versions ESPEC MIC CORP. data logger products versions RT-12N/RS-12N all firmware versions ESPEC MIC CORP. data logger products versions RT-22BN all firmware versions ESPEC MIC CORP. data logger products versions TEU-12N all firmware versions **Description** An improper authentication issue in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login to the product as a registered user. **Recommendations** For T&D Corporation data logger products versions TR-71W/72W all firmware versions, consider disabling remote access until a patch is available. For T&D Corporation data logger products versions RTR-5W all firmware versions, restrict access to the product to minimize the risk of exploitation. For T&D Corporation data logger products versions WDR-7 all firmware versions, avoid using default or weak passwords for registered users. For T&D Corporation data logger products versions WDR-3 all firmware versions, limit the number of login attempts to prevent brute-force attacks. For T&D Corporation data logger products versions WS-2 all firmware versions, implement additional authentication mechanisms, such as two-factor authentication. For ESPEC MIC CORP. data logger products versions RT-12N/RS-12N all firmware versions, consider changing default passwords and restricting access to the product. For ESPEC MIC CORP. data logger products versions RT-22BN all firmware versions, disable any unnecessary features or services that could be exploited. For ESPEC MIC CORP. data logger products versions TEU-12N all firmware versions, monitor user activity and login attempts to detect potential exploitation.