Katsunari Yoshioka

Researcher fromYokohama National University
#874of 53,633
232.4Total CVSS
Vulnerabilities · 34
Medium
21
High
7
Critical
6
PT-2025-3848
7.5
2025-01-15
Nec · Aterm Gb1200Pe · CVE-2025-0355
**Name of the Vulnerable Software and Affected Versions** NEC Corporation Aterm WG2600HS versions 1.7.2 and earlier NEC Corporation Aterm WF1200CRS versions 1.6.0 and earlier NEC Corporation Aterm WG1200CRS versions 1.5.0 and earlier NEC Corporation Aterm GB1200PE versions 1.3.0 and earlier NEC Corporation Aterm WG2600HP4 versions 1.4.2 and earlier NEC Corporation Aterm WG2600HM4 versions 1.4.2 and earlier NEC Corporation Aterm WG2600HS2 versions 1.3.2 and earlier NEC Corporation Aterm WX3000HP versions 2.4.2 and earlier NEC Corporation Aterm WX4200D5 versions 1.2.4 and earlier **Description** The issue allows an attacker to obtain a Wi-Fi password via the network due to missing authentication for a critical function. **Recommendations** For NEC Corporation Aterm WG2600HS versions 1.7.2 and earlier, update to a version later than 1.7.2. For NEC Corporation Aterm WF1200CRS versions 1.6.0 and earlier, update to a version later than 1.6.0. For NEC Corporation Aterm WG1200CRS versions 1.5.0 and earlier, update to a version later than 1.5.0. For NEC Corporation Aterm GB1200PE versions 1.3.0 and earlier, update to a version later than 1.3.0. For NEC Corporation Aterm WG2600HP4 versions 1.4.2 and earlier, update to a version later than 1.4.2. For NEC Corporation Aterm WG2600HM4 versions 1.4.2 and earlier, update to a version later than 1.4.2. For NEC Corporation Aterm WG2600HS2 versions 1.3.2 and earlier, update to a version later than 1.3.2. For NEC Corporation Aterm WX3000HP versions 2.4.2 and earlier, update to a version later than 2.4.2. For NEC Corporation Aterm WX4200D5 versions 1.2.4 and earlier, update to a version later than 1.2.4.
PT-2023-21090
9.8
2023-05-23
T&D · Wdr-3 · CVE-2023-27388
**Name of the Vulnerable Software and Affected Versions** T&D Corporation data logger products versions TR-71W/72W all firmware versions T&D Corporation data logger products versions RTR-5W all firmware versions T&D Corporation data logger products versions WDR-7 all firmware versions T&D Corporation data logger products versions WDR-3 all firmware versions T&D Corporation data logger products versions WS-2 all firmware versions ESPEC MIC CORP. data logger products versions RT-12N/RS-12N all firmware versions ESPEC MIC CORP. data logger products versions RT-22BN all firmware versions ESPEC MIC CORP. data logger products versions TEU-12N all firmware versions **Description** An improper authentication issue in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login to the product as a registered user. **Recommendations** For T&D Corporation data logger products versions TR-71W/72W all firmware versions, consider disabling remote access until a patch is available. For T&D Corporation data logger products versions RTR-5W all firmware versions, restrict access to the product to minimize the risk of exploitation. For T&D Corporation data logger products versions WDR-7 all firmware versions, avoid using default or weak passwords for registered users. For T&D Corporation data logger products versions WDR-3 all firmware versions, limit the number of login attempts to prevent brute-force attacks. For T&D Corporation data logger products versions WS-2 all firmware versions, implement additional authentication mechanisms, such as two-factor authentication. For ESPEC MIC CORP. data logger products versions RT-12N/RS-12N all firmware versions, consider changing default passwords and restricting access to the product. For ESPEC MIC CORP. data logger products versions RT-22BN all firmware versions, disable any unnecessary features or services that could be exploited. For ESPEC MIC CORP. data logger products versions TEU-12N all firmware versions, monitor user activity and login attempts to detect potential exploitation.