Vulnerability Description
Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to obtain the information stored in the product because the product is set to accept HTTP connections from the WAN side by default.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rakuten | Casa | ap_f_v1_4_1 |
References
- https://jvn.jp/en/jp/JVN46892984/index.htmlThird Party AdvisoryVDB Entry
- https://network.mobile.rakuten.co.jp/information/news/product/1033/Vendor Advisory
- https://jvn.jp/en/jp/JVN46892984/index.htmlThird Party AdvisoryVDB Entry
- https://network.mobile.rakuten.co.jp/information/news/product/1033/Vendor Advisory
FAQ
What is CVE-2022-26834?
CVE-2022-26834 is a vulnerability with a CVSS score of 7.5 (HIGH). Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to obtain the information stored in the product because the product is set to accept H...
How severe is CVE-2022-26834?
CVE-2022-26834 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-26834?
Check the references section above for vendor advisories and patch information. Affected products include: Rakuten Casa.