Vulnerability Description
The WPS implementation on I-O DATA DEVICE WN-GDN/R3, WN-GDN/R3-C, WN-GDN/R3-S, and WN-GDN/R3-U devices does not limit PIN guesses, which allows remote attackers to obtain network access via a brute-force attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Iodata | Wn-Gdn\/R3 Firmware | - |
| Iodata | Wn-Gdn\/R3 | - |
| Iodata | Wn-Gdn\/R3-C | - |
| Iodata | Wn-Gdn\/R3-S | - |
| Iodata | Wn-Gdn\/R3-U | - |
Related Weaknesses (CWE)
References
- http://jvn.jp/en/jp/JVN25674893/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000061Vendor Advisory
- http://www.iodata.jp/support/information/2016/wn-gdnr3_bfa/Vendor Advisory
- http://jvn.jp/en/jp/JVN25674893/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000061Vendor Advisory
- http://www.iodata.jp/support/information/2016/wn-gdnr3_bfa/Vendor Advisory
FAQ
What is CVE-2016-1206?
CVE-2016-1206 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The WPS implementation on I-O DATA DEVICE WN-GDN/R3, WN-GDN/R3-C, WN-GDN/R3-S, and WN-GDN/R3-U devices does not limit PIN guesses, which allows remote attackers to obtain network access via a brute-fo...
How severe is CVE-2016-1206?
CVE-2016-1206 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-1206?
Check the references section above for vendor advisories and patch information. Affected products include: Iodata Wn-Gdn\/R3 Firmware, Iodata Wn-Gdn\/R3, Iodata Wn-Gdn\/R3-C, Iodata Wn-Gdn\/R3-S, Iodata Wn-Gdn\/R3-U.