PT-2022-18089 · Rakuten · Rakuten Casa
Masaki Tagawa
·
Published
2022-06-13
·
Updated
2023-08-08
·
CVE-2022-26834
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Rakuten Casa version AP F V1 4 1
Rakuten Casa version AP F V2 0 0
Description
The issue is related to improper access control, allowing a remote attacker to obtain stored information because the product accepts HTTP connections from the WAN side by default.
Recommendations
For Rakuten Casa version AP F V1 4 1, restrict access to HTTP connections from the WAN side to minimize the risk of exploitation.
For Rakuten Casa version AP F V2 0 0, restrict access to HTTP connections from the WAN side to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rakuten Casa