HIGH🇵🇱 Wersja polska

CVE-2022-28704

CVSS 7.2v3.1pub. 2022-06-13upd. 2024-11-21

Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to log in with the root privilege and perform an arbitrary operation if the product is in its default settings in which is set to accept SSH connections from the WAN side, and is also connected to the Internet with the authentication information unchanged from the default settings.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Rakuten Casa

    APP
    Rakuten
    ap_f_v1_4_1ap_f_v2_0_0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-29525CRITICAL9.8PL ✓same product

Rakuten Casa — zakodowane na stałe hasło umożliwia zdalny dostęp root

CVE-2022-26834HIGH7.5same product

Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attac...

CVE-2025-13476CRITICAL9.8PL ✓same vendor

Rakuten Viber: statyczny fingerprint TLS umożliwia identyfikację ruchu proxy

CVE-2020-14049HIGH7.5same vendor

Viber for Windows up to 13.2.0.39 does not properly quote its custom URI handler. A malicious website could la...

CVE-2019-18800HIGH8.8same vendor

Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Vib...