Vulnerability Description
Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 uses a hard-coded credential which may allow a remote unauthenticated attacker to log in with the root privilege and perform an arbitrary operation.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rakuten | Casa | ap_f_v1_4_1 |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/jp/JVN46892984/index.htmlThird Party AdvisoryVDB Entry
- https://network.mobile.rakuten.co.jp/information/news/product/1033/Vendor Advisory
- https://jvn.jp/en/jp/JVN46892984/index.htmlThird Party AdvisoryVDB Entry
- https://network.mobile.rakuten.co.jp/information/news/product/1033/Vendor Advisory
FAQ
What is CVE-2022-29525?
CVE-2022-29525 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 uses a hard-coded credential which may allow a remote unauthenticated attacker to log in with the root privilege and perform an arbitrary operation.
How severe is CVE-2022-29525?
CVE-2022-29525 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-29525?
Check the references section above for vendor advisories and patch information. Affected products include: Rakuten Casa.