CVE-2022-28704
Dashboard / Vulnerabilities / CVE-2022-28704
CVE-2022-28704
Published: 13 Jun 2022Last Modified: 11 Mar 2026
Summary:
Details: Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to log in with the root privilege and perform an arbitrary operation if the product is in its default settings in which is set to accept SSH connections from the WAN side, and is also connected to the Internet with the authentication information unchanged from the default settings.
References: , https://jvn.jp/en/jp/JVN46892984/index.html, https://network.mobile.rakuten.co.jp/information/news/product/1033/
Affected packages
Package
Name:
Purl:
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
