PT-2023-21090 · T&D+1 · Wdr-3+7
Junnosuke Kushibiki
+5
·
Published
2023-05-23
·
Updated
2025-01-31
·
CVE-2023-27388
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
T&D Corporation data logger products versions TR-71W/72W all firmware versions
T&D Corporation data logger products versions RTR-5W all firmware versions
T&D Corporation data logger products versions WDR-7 all firmware versions
T&D Corporation data logger products versions WDR-3 all firmware versions
T&D Corporation data logger products versions WS-2 all firmware versions
ESPEC MIC CORP. data logger products versions RT-12N/RS-12N all firmware versions
ESPEC MIC CORP. data logger products versions RT-22BN all firmware versions
ESPEC MIC CORP. data logger products versions TEU-12N all firmware versions
Description
An improper authentication issue in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login to the product as a registered user.
Recommendations
For T&D Corporation data logger products versions TR-71W/72W all firmware versions, consider disabling remote access until a patch is available.
For T&D Corporation data logger products versions RTR-5W all firmware versions, restrict access to the product to minimize the risk of exploitation.
For T&D Corporation data logger products versions WDR-7 all firmware versions, avoid using default or weak passwords for registered users.
For T&D Corporation data logger products versions WDR-3 all firmware versions, limit the number of login attempts to prevent brute-force attacks.
For T&D Corporation data logger products versions WS-2 all firmware versions, implement additional authentication mechanisms, such as two-factor authentication.
For ESPEC MIC CORP. data logger products versions RT-12N/RS-12N all firmware versions, consider changing default passwords and restricting access to the product.
For ESPEC MIC CORP. data logger products versions RT-22BN all firmware versions, disable any unnecessary features or services that could be exploited.
For ESPEC MIC CORP. data logger products versions TEU-12N all firmware versions, monitor user activity and login attempts to detect potential exploitation.
Fix
Incorrect Authorization
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rt-12N/Rs-12N
Rt-22Bn
Rtr-5W
Teu-12N
Tr-71W/72W
Wdr-3
Wdr-7
Ws-2