PT-2022-18089 · Rakuten · Rakuten Casa

Masaki Tagawa

·

Published

2022-06-13

·

Updated

2023-08-08

·

CVE-2022-26834

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Rakuten Casa version AP F V1 4 1 Rakuten Casa version AP F V2 0 0
Description The issue is related to improper access control, allowing a remote attacker to obtain stored information because the product accepts HTTP connections from the WAN side by default.
Recommendations For Rakuten Casa version AP F V1 4 1, restrict access to HTTP connections from the WAN side to minimize the risk of exploitation. For Rakuten Casa version AP F V2 0 0, restrict access to HTTP connections from the WAN side to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-26834

Affected Products

Rakuten Casa