#VU80004 Improper Authentication in Rakuten WiFi Pocket - CVE-2023-40282

 

#VU80004 Improper Authentication in Rakuten WiFi Pocket - CVE-2023-40282

Published: August 25, 2023


Vulnerability identifier: #VU80004
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2023-40282
CWE-ID: CWE-287
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
Rakuten WiFi Pocket
Software vendor:
Rakuten Mobile

Description

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests in the Management Screen. A remote attacker on the local network can bypass authentication process and gain unauthorized access to sensitive information.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links