Hard-Coded Credential Vulnerability in Rakuten Casa Devices
CVE-2022-29525

9.8CRITICAL

Key Information:

Vendor
CVE Published:
13 June 2022

What is CVE-2022-29525?

A security flaw in certain Rakuten Casa devices allows a remote, unauthenticated attacker to exploit hard-coded credentials to gain root privileges. This vulnerability enables malicious actors to execute arbitrary operations on the affected systems, posing significant risks to device security and user data integrity.

Affected Version(s)

Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.