#VU80004 Improper Authentication in Rakuten WiFi Pocket - CVE-2023-40282
Published: August 25, 2023
Vulnerability identifier: #VU80004
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2023-40282
CWE-ID: CWE-287
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerable software:
Rakuten WiFi Pocket
Rakuten WiFi Pocket
Software vendor:
Rakuten Mobile
Rakuten Mobile
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests in the Management Screen. A remote attacker on the local network can bypass authentication process and gain unauthorized access to sensitive information.
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.