Improper Authentication Vulnerability in Rakuten WiFi Pocket
CVE-2023-40282

5.4MEDIUM

Key Information:

Vendor
CVE Published:
23 August 2023

What is CVE-2023-40282?

An improper authentication vulnerability exists in all versions of the Rakuten WiFi Pocket device. This flaw allows network-adjacent attackers to access the device's Management Screen without proper validation. By exploiting this vulnerability, attackers could potentially retrieve sensitive information or alter device settings, posing significant security risks to users.

Affected Version(s)

Rakuten WiFi Pocket all versions

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-40282 : Improper Authentication Vulnerability in Rakuten WiFi Pocket