Search

Find a vulnerability

Search criteria

    38 vulnerabilities by kddi

    JVNDB-2026-000069

    Vulnerability from jvndb - Published: 2026-05-13 06:41 - Updated:2026-05-13 06:41
    Severity
    Summary
    Android App "Anshin Filter for au" vulnerable to cleartext transmission of sensitive information
    Details
    Android App "Anshin Filter for au" provided by KDDI CORPORATION contains the following vulnerability.
    • Cleartext transmission of sensitive information (CWE-319) - CVE-2026-41281
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-000069.html",
      "dc:date": "2026-05-13T15:41+09:00",
      "dcterms:issued": "2026-05-13T15:41+09:00",
      "dcterms:modified": "2026-05-13T15:41+09:00",
      "description": "Android App \"Anshin Filter for au\" provided by KDDI CORPORATION contains the following vulnerability.\u003ca href=\u0027https://cwe.mitre.org/data/definitions/319.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003cul\u003e\u003cli\u003eCleartext transmission of sensitive information (CWE-319) - CVE-2026-41281\u003c/li\u003e\u003c/ul\u003e",
      "link": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-000069.html",
      "sec:cpe": {
        "#text": "cpe:/a:kddi:anshin_filter_for_au_for_android",
        "@product": "Android App \"Anshin Filter for au\"",
        "@vendor": "KDDI",
        "@version": "2.2"
      },
      "sec:cvss": {
        "@score": "4.8",
        "@severity": "Medium",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2026-000069",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN24167657/index.html",
          "@id": "JVN#24167657",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-41281",
          "@id": "CVE-2026-41281",
          "@source": "CVE"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "Android App \"Anshin Filter for au\" vulnerable to cleartext transmission of sensitive information"
    }

    JVNDB-2026-000043

    Vulnerability from jvndb - Published: 2026-03-25 09:41 - Updated:2026-03-25 09:41
    Severity
    Summary
    SHARP routers missing authentication for some web APIs
    Details
    SHARP routers do not perform authentication for some web APIs. Those web APIs provide device information, and the initial administrative password is based on a part of the device information.
    • Missing authentication for critical function (CWE-306) - CVE-2026-32326
    Shota Zaizen reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-000043.html",
      "dc:date": "2026-03-25T18:41+09:00",
      "dcterms:issued": "2026-03-25T18:41+09:00",
      "dcterms:modified": "2026-03-25T18:41+09:00",
      "description": "SHARP routers do not perform authentication for some web APIs.\r\nThose web APIs provide device information, and the initial administrative password is based on a part of the device information.\u003ca href=\u0027https://cwe.mitre.org/data/definitions/306.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003cul\u003e\u003cli\u003eMissing authentication for critical function (CWE-306) - CVE-2026-32326\u003c/li\u003e\u003c/ul\u003eShota Zaizen reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-000043.html",
      "sec:cpe": [
        {
          "#text": "cpe:/o:kddi:speed_wi-fi_5g_x01",
          "@product": "Speed Wi-Fi 5G X01",
          "@vendor": "KDDI",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nttdocomo:home_5g_hr01",
          "@product": "home 5G HR01",
          "@vendor": "NTT DOCOMO, INC.",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nttdocomo:home_5g_hr02",
          "@product": "home 5G HR02",
          "@vendor": "NTT DOCOMO, INC.",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nttdocomo:wi-fi_station_sh-52a_firmware",
          "@product": "Wi-Fi STATION SH-52A",
          "@vendor": "NTT DOCOMO, INC.",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nttdocomo:wi-fi_station_sh-52b_firmware",
          "@product": "Wi-Fi STATION SH-52B",
          "@vendor": "NTT DOCOMO, INC.",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nttdocomo:wi-fi_station_sh-54c_firmware",
          "@product": "Wi-Fi STATION SH-54C",
          "@vendor": "NTT DOCOMO, INC.",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:softbank:5gmobile_wi-fi_router_sh-u01",
          "@product": "5G Mobile Router SH-U01",
          "@vendor": "SoftBank",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:softbank:pocket_wifi_5g_a503sh",
          "@product": "Pocket WiFi 5G A503SH versions",
          "@vendor": "SoftBank",
          "@version": "2.2"
        }
      ],
      "sec:cvss": {
        "@score": "5.7",
        "@severity": "Medium",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2026-000043",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN49524110/index.html",
          "@id": "JVN#49524110",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-32326",
          "@id": "CVE-2026-32326",
          "@source": "CVE"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "SHARP routers missing authentication for some web APIs"
    }

    JVNDB-2025-000097

    Vulnerability from jvndb - Published: 2025-11-17 05:09 - Updated:2025-11-17 05:09
    Severity
    Summary
    "Dejira" App for iOS vulnerable to improper server certificate verification
    Details
    "Dejira" App for iOS provided by KDDI CORPORATION contains the following vulnerability.
    • Improper server certificate verification (CWE-295)
    Tsuyoshi Ogawa of SIE Co.,Ltd reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-000097.html",
      "dc:date": "2025-11-17T14:09+09:00",
      "dcterms:issued": "2025-11-17T14:09+09:00",
      "dcterms:modified": "2025-11-17T14:09+09:00",
      "description": "\"Dejira\" App for iOS provided by KDDI CORPORATION contains the following vulnerability.\r\n\u003cul\u003e\u003cli\u003eImproper server certificate verification (CWE-295)\u003c/li\u003e\u003c/ul\u003e\r\nTsuyoshi Ogawa of SIE Co.,Ltd reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-000097.html",
      "sec:cpe": {
        "#text": "cpe:/a:kddi:dejira_app",
        "@product": "\"Dejira\" App for iOS",
        "@vendor": "KDDI",
        "@version": "2.2"
      },
      "sec:cvss": {
        "@score": "4.8",
        "@severity": "Medium",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2025-000097",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN54005037/index.html",
          "@id": "JVN#54005037",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2025-60022",
          "@id": "CVE-2025-60022",
          "@source": "CVE"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "\"Dejira\" App for iOS vulnerable to improper server certificate verification"
    }

    JVNDB-2025-000018

    Vulnerability from jvndb - Published: 2025-03-19 06:33 - Updated:2025-03-28 02:48
    Severity
    Summary
    Multiple vulnerabilities in home gateway HGW-BL1500HM
    Details
    Home gateway HGW-BL1500HM provided by KDDI CORPORATION contains multiple vulnerabilities listed below.
    • Stored cross-site scripting in the NickName registration screen (CWE-79) - CVE-2025-27567
    • Stored cross-site scripting in the USB storage file-sharing function (CWE-79) - CVE-2025-27574
    • Path traversal in the file/folder listing process of the USB storage file-sharing function (CWE-22) - CVE-2025-27716
    • Path traversal in the file upload process of the USB storage file-sharing function (CWE-22) - CVE-2025-27718
    • Path traversal in the file download process of the USB storage file-sharing function (CWE-22) - CVE-2025-27726
    • Path traversal in the file deletion process of the USB storage file-sharing function (CWE-22) - CVE-2025-27932
    Huiseong Seo reported these vulnerabilities to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-000018.html",
      "dc:date": "2025-03-28T11:48+09:00",
      "dcterms:issued": "2025-03-19T15:33+09:00",
      "dcterms:modified": "2025-03-28T11:48+09:00",
      "description": "Home gateway HGW-BL1500HM provided by KDDI CORPORATION contains multiple vulnerabilities listed below.\r\n\u003cul\u003e\u003cli\u003eStored cross-site scripting in the NickName registration screen (CWE-79) - CVE-2025-27567\u003c/li\u003e\u003cli\u003eStored cross-site scripting in the USB storage file-sharing function (CWE-79) - CVE-2025-27574\u003c/li\u003e\u003cli\u003ePath traversal in the file/folder listing process of the USB storage file-sharing function (CWE-22) - CVE-2025-27716\u003c/li\u003e\u003cli\u003ePath traversal in the file upload process of the USB storage file-sharing function (CWE-22) - CVE-2025-27718\u003c/li\u003e\u003cli\u003ePath traversal in the file download process of the USB storage file-sharing function (CWE-22) -   CVE-2025-27726\u003c/li\u003e\u003cli\u003ePath traversal in the file deletion process of the USB storage file-sharing function (CWE-22) - CVE-2025-27932\u003c/li\u003e\u003c/ul\u003e\r\nHuiseong Seo reported these vulnerabilities to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-000018.html",
      "sec:cpe": {
        "#text": "cpe:/o:kddi:hgw-bl1500hm",
        "@product": "HGW-BL1500HM",
        "@vendor": "KDDI",
        "@version": "2.2"
      },
      "sec:cvss": {
        "@score": "8.8",
        "@severity": "High",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2025-000018",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN04278547/index.html",
          "@id": "JVN#04278547",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2025-27567",
          "@id": "CVE-2025-27567",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2025-27574",
          "@id": "CVE-2025-27574",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2025-27716",
          "@id": "CVE-2025-27716",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2025-27718",
          "@id": "CVE-2025-27718",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2025-27726",
          "@id": "CVE-2025-27726",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2025-27932",
          "@id": "CVE-2025-27932",
          "@source": "CVE"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-22",
          "@title": "Path Traversal(CWE-22)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-79",
          "@title": "Cross-site Scripting(CWE-79)"
        }
      ],
      "title": "Multiple vulnerabilities in home gateway HGW-BL1500HM"
    }

    JVNDB-2024-000123

    Vulnerability from jvndb - Published: 2024-11-29 06:30 - Updated:2024-11-29 06:30
    Severity
    Summary
    Multiple FCNT Android devices vulnerable to authentication bypass
    Details
    Multiple FCNT Android devices provide security features such as "privacy mode" where arbitrary applications can be set not to be displayed, etc. The devices contain an authentication bypass vulnerability (CWE-306), where, under certain conditions, the setting pages may be accessed without authentication.
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2024/JVNDB-2024-000123.html",
      "dc:date": "2024-11-29T15:30+09:00",
      "dcterms:issued": "2024-11-29T15:30+09:00",
      "dcterms:modified": "2024-11-29T15:30+09:00",
      "description": "Multiple FCNT Android devices provide security features such as \"privacy mode\" where arbitrary applications can be set not to be displayed, etc.\r\nThe devices contain an authentication bypass vulnerability (CWE-306), where, under certain conditions, the setting pages may be accessed without authentication.",
      "link": "https://jvndb.jvn.jp/en/contents/2024/JVNDB-2024-000123.html",
      "sec:cpe": [
        {
          "#text": "cpe:/o:kddi:arrows",
          "@product": "arrows",
          "@vendor": "KDDI",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nttdocomo:arrows",
          "@product": "arrows",
          "@vendor": "NTT DOCOMO, INC.",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nttdocomo:arrows",
          "@product": "arrows",
          "@vendor": "NTT DOCOMO, INC.",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:softbank:arrows",
          "@product": "arrows",
          "@vendor": "SoftBank",
          "@version": "2.2"
        }
      ],
      "sec:cvss": {
        "@score": "3.1",
        "@severity": "Low",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2024-000123",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN43845108/index.html",
          "@id": "JVN#43845108",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2024-53701",
          "@id": "CVE-2024-53701",
          "@source": "CVE"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "Multiple FCNT Android devices vulnerable to authentication bypass"
    }

    JVNDB-2024-003016

    Vulnerability from jvndb - Published: 2024-03-25 08:28 - Updated:2025-03-28 03:01
    Severity
    Summary
    Multiple vulnerabilities in home gateway HGW BL1500HM
    Details
    Home gateway HGW BL1500HM provided by KDDI CORPORATION contains multiple vulnerabilities listed below. * Use of weak credentials (CWE-1391) - CVE-2024-21865, CVE-2024-29071 * Command injection (CWE-77) - CVE-2024-28041 Chuya Hayakawa of 00One, Inc. reported these vulnerabilities to JPCERT/CC. JPCERT/CC coordinated with the developer.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2024/JVNDB-2024-003016.html",
      "dc:date": "2025-03-28T12:01+09:00",
      "dcterms:issued": "2024-03-25T17:28+09:00",
      "dcterms:modified": "2025-03-28T12:01+09:00",
      "description": "Home gateway HGW BL1500HM provided by KDDI CORPORATION contains multiple vulnerabilities listed below.\r\n\r\n  * Use of weak credentials (CWE-1391) - CVE-2024-21865, CVE-2024-29071\r\n  * Command injection (CWE-77) - CVE-2024-28041\r\n\r\nChuya Hayakawa of 00One, Inc. reported these vulnerabilities to JPCERT/CC.\r\nJPCERT/CC coordinated with the developer.",
      "link": "https://jvndb.jvn.jp/en/contents/2024/JVNDB-2024-003016.html",
      "sec:cpe": {
        "#text": "cpe:/o:kddi:hgw_bl1500hm_firmware",
        "@product": "HGW BL1500HM firmware",
        "@vendor": "KDDI",
        "@version": "2.2"
      },
      "sec:cvss": {
        "@score": "8.8",
        "@severity": "High",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2024-003016",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/vu/JVNVU93546510/index.html",
          "@id": "JVNVU#93546510",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2024-21865",
          "@id": "CVE-2024-21865",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2024-28041",
          "@id": "CVE-2024-28041",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2024-29071",
          "@id": "CVE-2024-29071",
          "@source": "CVE"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/1391.html",
          "@id": "CWE-1391",
          "@title": "Use of Weak Credentials(CWE-1391)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/77.html",
          "@id": "CWE-77",
          "@title": "Command Injection(CWE-77)"
        }
      ],
      "title": "Multiple vulnerabilities in home gateway HGW BL1500HM"
    }

    JVNDB-2024-001804

    Vulnerability from jvndb - Published: 2024-02-06 06:02 - Updated:2024-03-11 08:32
    Severity
    Summary
    Multiple buffer overflow vulnerabilities in HOME SPOT CUBE2
    Details
    HOME SPOT CUBE2 provided by KDDI CORPORATION contains multiple vulnerabilities listed below. * Stack-based buffer overflow (CWE-121) - CVE-2024-21780 * Heap-based buffer overflow (CWE-122) - CVE-2024-23978 Chuya Hayakawa of 00One, Inc. reported these vulnerabilities to JPCERT/CC. JPCERT/CC coordinated with the developer.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2024/JVNDB-2024-001804.html",
      "dc:date": "2024-03-11T17:32+09:00",
      "dcterms:issued": "2024-02-06T15:02+09:00",
      "dcterms:modified": "2024-03-11T17:32+09:00",
      "description": "HOME SPOT CUBE2 provided by KDDI CORPORATION contains multiple vulnerabilities listed below.\r\n\r\n  * Stack-based buffer overflow (CWE-121) - CVE-2024-21780\r\n  * Heap-based buffer overflow (CWE-122) - CVE-2024-23978\r\n\r\nChuya Hayakawa of 00One, Inc. reported these vulnerabilities to JPCERT/CC.\r\nJPCERT/CC coordinated with the developer.",
      "link": "https://jvndb.jvn.jp/en/contents/2024/JVNDB-2024-001804.html",
      "sec:cpe": {
        "#text": "cpe:/o:kddi:home_spot_cube_2_firmware",
        "@product": "HOME SPOT CUBE2 firmware",
        "@vendor": "KDDI",
        "@version": "2.2"
      },
      "sec:cvss": {
        "@score": "8.8",
        "@severity": "High",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2024-001804",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/vu/JVNVU93740658/index.html",
          "@id": "JVNVU#93740658",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2024-21780",
          "@id": "CVE-2024-21780",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2024-23978",
          "@id": "CVE-2024-23978",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2024-21780",
          "@id": "CVE-2024-21780",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2024-23978",
          "@id": "CVE-2024-23978",
          "@source": "NVD"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/121.html",
          "@id": "CWE-121",
          "@title": "Stack-based Buffer Overflow(CWE-121)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/122.html",
          "@id": "CWE-122",
          "@title": "Heap-based Buffer Overflow(CWE-122)"
        }
      ],
      "title": "Multiple buffer overflow vulnerabilities in HOME SPOT CUBE2"
    }

    JVNDB-2022-000101

    Vulnerability from jvndb - Published: 2022-12-21 05:13 - Updated:2022-12-21 05:13
    Severity
    Summary
    +Message App improper handling of Unicode control characters
    Details
    +Message App displays text unprocessed, even when control characters are contained, and the text is shown based on Unicode control character's specifications. Therefore, a crafted text may display misleading web links (CWE-451). Akaki Tsunoda reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-000101.html",
      "dc:date": "2022-12-21T14:13+09:00",
      "dcterms:issued": "2022-12-21T14:13+09:00",
      "dcterms:modified": "2022-12-21T14:13+09:00",
      "description": "+Message App displays text unprocessed, even when control characters are contained, and the text is shown based on Unicode control character\u0027s specifications.\r\nTherefore, a crafted text may display misleading web links (CWE-451).\r\n\r\nAkaki Tsunoda reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-000101.html",
      "sec:cpe": [
        {
          "#text": "cpe:/a:kddi:%2b_message",
          "@product": "+Message (PlusMessage)",
          "@vendor": "KDDI",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:nttdocomo:%2b_message",
          "@product": "+Message (PlusMessage)",
          "@vendor": "NTT DOCOMO, INC.",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:softbank:%2b_message",
          "@product": "+Message (PlusMessage)",
          "@vendor": "SoftBank",
          "@version": "2.2"
        }
      ],
      "sec:cvss": [
        {
          "@score": "4.3",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "@version": "2.0"
        },
        {
          "@score": "4.3",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
          "@version": "3.0"
        }
      ],
      "sec:identifier": "JVNDB-2022-000101",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN43561812/index.html",
          "@id": "JVN#43561812",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2022-43543",
          "@id": "CVE-2022-43543",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-43543",
          "@id": "CVE-2022-43543",
          "@source": "NVD"
        },
        {
          "#text": "https://unicode.org/reports/tr36/",
          "@id": "Unicode Technical Report #36",
          "@source": "Related document"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "+Message App improper handling of Unicode control characters"
    }

    JVNDB-2022-000049

    Vulnerability from jvndb - Published: 2022-06-29 04:42 - Updated:2024-06-17 01:45
    Severity
    Summary
    HOME SPOT CUBE2 vulnerable to OS command injection
    Details
    HOME SPOT CUBE2 provided by KDDI CORPORATION contains an OS command injection vulnerability (CWE-78) due to improper processing of data received from DHCP server. Alice Rose reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-000049.html",
      "dc:date": "2024-06-17T10:45+09:00",
      "dcterms:issued": "2022-06-29T13:42+09:00",
      "dcterms:modified": "2024-06-17T10:45+09:00",
      "description": "HOME SPOT CUBE2 provided by KDDI CORPORATION contains an OS command injection vulnerability (CWE-78) due to improper processing of data received from DHCP server.\r\n\r\nAlice Rose reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-000049.html",
      "sec:cpe": {
        "#text": "cpe:/h:kddi:home_spot_cube_2",
        "@product": "HOME SPOT CUBE2",
        "@vendor": "KDDI",
        "@version": "2.2"
      },
      "sec:cvss": [
        {
          "@score": "5.8",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "AV:A/AC:L/Au:N/C:P/I:P/A:P",
          "@version": "2.0"
        },
        {
          "@score": "8.8",
          "@severity": "High",
          "@type": "Base",
          "@vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "@version": "3.0"
        }
      ],
      "sec:identifier": "JVNDB-2022-000049",
      "sec:references": [
        {
          "#text": "http://jvn.jp/en/jp/JVN41017328/index.html",
          "@id": "JVN#41017328",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2022-33948",
          "@id": "CVE-2022-33948",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-33948",
          "@id": "CVE-2022-33948",
          "@source": "NVD"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-78",
          "@title": "OS Command Injection(CWE-78)"
        }
      ],
      "title": "HOME SPOT CUBE2 vulnerable to OS command injection"
    }

    JVNDB-2019-000053

    Vulnerability from jvndb - Published: 2019-08-23 06:57 - Updated:2019-10-08 08:35
    Severity
    Summary
    Smart TV Box fails to restrict access permissions
    Details
    Smart TV Box provided by KDDI CORPORATION enables access to Android Debug Bridge via port 5555/TCP of LAN side interface. When a cable television provider sets up Smart TV Box at an individual residence, direct access from outside to the LAN side interface of Smart TV Box is disabled. However if the original setting is changed later, for example, LAN side interface connection to internet directly is enabled, access to Android Debug Bridge via port 5555/TCP of LAN side interface becomes enabled. As a result, arbitrary operations without users intent becomes possible, and a remote attacker may conduct arbitrary operations on the device. Yoshiki Mori and Masaki Kubo of Cybersecurity Laboratory, National Institute of Information and Communications Technology reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2019/JVNDB-2019-000053.html",
      "dc:date": "2019-10-08T17:35+09:00",
      "dcterms:issued": "2019-08-23T15:57+09:00",
      "dcterms:modified": "2019-10-08T17:35+09:00",
      "description": "Smart TV Box provided by KDDI CORPORATION enables access to Android Debug Bridge via port 5555/TCP of LAN side interface.\r\nWhen a cable television provider sets up Smart TV Box at an individual residence, direct access from outside to the LAN side interface of Smart TV Box is disabled.  However if the original setting is changed later, for example, LAN side interface connection to internet directly is enabled, access to Android Debug Bridge via port 5555/TCP of LAN side interface becomes enabled.  As a result, arbitrary operations without users intent becomes possible, and a remote attacker may conduct arbitrary operations on the device.\r\n\r\nYoshiki Mori and Masaki Kubo of Cybersecurity Laboratory, National Institute of Information and Communications Technology reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2019/JVNDB-2019-000053.html",
      "sec:cpe": {
        "#text": "cpe:/o:kddi:smart_tv_box_firmware",
        "@product": "Smart TV Box",
        "@vendor": "KDDI",
        "@version": "2.2"
      },
      "sec:cvss": [
        {
          "@score": "6.8",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "@version": "2.0"
        },
        {
          "@score": "7.3",
          "@severity": "High",
          "@type": "Base",
          "@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
          "@version": "3.0"
        }
      ],
      "sec:identifier": "JVNDB-2019-000053",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN17127920/index.html",
          "@id": "JVN#17127920",
          "@source": "JVN"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6005",
          "@id": "CVE-2019-6005",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2019-6005",
          "@id": "CVE-2019-6005",
          "@source": "NVD"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "Smart TV Box fails to restrict access permissions"
    }

    JVNDB-2018-000100

    Vulnerability from jvndb - Published: 2018-09-27 07:52 - Updated:2019-08-27 08:22
    Severity
    Summary
    +Message App fails to verify SSL server certificates
    Details
    +Message App fails to verify SSL server certificates. ma.la of LINE Corporation reported this vulnerability to the developer, and also to IPA in order to notify users of its solution through JVN. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2018/JVNDB-2018-000100.html",
      "dc:date": "2019-08-27T17:22+09:00",
      "dcterms:issued": "2018-09-27T16:52+09:00",
      "dcterms:modified": "2019-08-27T17:22+09:00",
      "description": "+Message App fails to verify SSL server certificates.\r\n\r\nma.la of LINE Corporation reported this vulnerability to the developer, and also to IPA in order to notify users of its solution through JVN.\r\n JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2018/JVNDB-2018-000100.html",
      "sec:cpe": [
        {
          "#text": "cpe:/a:kddi:%2b_message",
          "@product": "+Message (PlusMessage)",
          "@vendor": "KDDI",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:nttdocomo:%2b_message",
          "@product": "+Message (PlusMessage)",
          "@vendor": "NTT DOCOMO, INC.",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:softbank:%2b_message",
          "@product": "+Message (PlusMessage)",
          "@vendor": "SoftBank",
          "@version": "2.2"
        }
      ],
      "sec:cvss": [
        {
          "@score": "4.0",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "AV:N/AC:H/Au:N/C:P/I:P/A:N",
          "@version": "2.0"
        },
        {
          "@score": "4.8",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
          "@version": "3.0"
        }
      ],
      "sec:identifier": "JVNDB-2018-000100",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN37288228/",
          "@id": "JVN#37288228",
          "@source": "JVN"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0691",
          "@id": "CVE-2018-0691",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2018-0691",
          "@id": "CVE-2018-0691",
          "@source": "NVD"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "+Message App fails to verify SSL server certificates"
    }

    JVNDB-2018-000009

    Vulnerability from jvndb - Published: 2018-02-06 06:05 - Updated:2018-04-11 03:13
    Severity
    Summary
    The installer of Anshin net security for Windows may insecurely load Dynamic Link Libraries
    Details
    Anshin net security for Windows provided by KDDI CORPORATION is an Internet Security suite. The installer of Anshin net security for Windows contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427). Eili Masami of Tachibana Lab. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2018/JVNDB-2018-000009.html",
      "dc:date": "2018-04-11T12:13+09:00",
      "dcterms:issued": "2018-02-06T15:05+09:00",
      "dcterms:modified": "2018-04-11T12:13+09:00",
      "description": "Anshin net security for Windows provided by KDDI CORPORATION is an Internet Security suite. The installer of Anshin net security for Windows contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427).\r\n\r\nEili Masami of Tachibana Lab. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2018/JVNDB-2018-000009.html",
      "sec:cpe": {
        "#text": "cpe:/a:kddi:anshin_net_security",
        "@product": "Anshin net security",
        "@vendor": "KDDI",
        "@version": "2.2"
      },
      "sec:cvss": [
        {
          "@score": "6.8",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "@version": "2.0"
        },
        {
          "@score": "7.8",
          "@severity": "High",
          "@type": "Base",
          "@vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "@version": "3.0"
        }
      ],
      "sec:identifier": "JVNDB-2018-000009",
      "sec:references": [
        {
          "#text": "http://jvn.jp/en/jp/JVN70615027/index.html",
          "@id": "JVN#70615027",
          "@source": "JVN"
        },
        {
          "#text": "https://jvn.jp/en/ta/JVNTA91240916/index.html",
          "@id": "JVNTA#91240916",
          "@source": "JVN"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0517",
          "@id": "CVE-2018-0517",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2018-0517",
          "@id": "CVE-2018-0517",
          "@source": "NVD"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "The installer of Anshin net security for Windows may insecurely load Dynamic Link Libraries"
    }

    JVNDB-2017-000191

    Vulnerability from jvndb - Published: 2017-08-08 06:35 - Updated:2018-02-14 03:14
    Severity
    Summary
    Installer of Qua station connection tool for Windows may insecurely load Dynamic Link Libraries
    Details
    Qua station provided KDDI CORPORATION is a 4G LTE photostrage. Qua station connection tool is used to view data saved on Qua station from a PC and/or save data on a PC. Installer of Qua station connection tool for Windows contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427). Eili Masami of Tachibana Lab. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000191.html",
      "dc:date": "2018-02-14T12:14+09:00",
      "dcterms:issued": "2017-08-08T15:35+09:00",
      "dcterms:modified": "2018-02-14T12:14+09:00",
      "description": "Qua station provided KDDI CORPORATION is a 4G LTE photostrage. Qua station connection tool is used to view data saved on Qua station from a PC and/or save data on a PC.  Installer of Qua station connection tool for Windows contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427).\r\n\r\nEili Masami of Tachibana Lab. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000191.html",
      "sec:cpe": {
        "#text": "cpe:/h:kddi:qua_station",
        "@product": "Qua station connection tool",
        "@vendor": "KDDI",
        "@version": "2.2"
      },
      "sec:cvss": [
        {
          "@score": "6.8",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "@version": "2.0"
        },
        {
          "@score": "7.8",
          "@severity": "High",
          "@type": "Base",
          "@vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "@version": "3.0"
        }
      ],
      "sec:identifier": "JVNDB-2017-000191",
      "sec:references": [
        {
          "#text": "http://jvn.jp/en/jp/JVN81659403/index.html",
          "@id": "JVN#81659403",
          "@source": "JVN"
        },
        {
          "#text": "https://jvn.jp/en/ta/JVNTA91240916/index.html",
          "@id": "JVNTA#91240916",
          "@source": "JVN"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2289",
          "@id": "CVE-2017-2289",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2017-2289",
          "@id": "CVE-2017-2289",
          "@source": "NVD"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "Installer of Qua station connection tool for Windows may insecurely load Dynamic Link Libraries"
    }

    JVNDB-2017-000138

    Vulnerability from jvndb - Published: 2017-06-21 04:45 - Updated:2018-02-14 02:59
    Severity
    Summary
    HOME SPOT CUBE2 vulnerable to improper authentication in WebUI
    Details
    HOME SPOT CUBE2 provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE2 contains improper authentication in WebUI. Taizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000138.html",
      "dc:date": "2018-02-14T11:59+09:00",
      "dcterms:issued": "2017-06-21T13:45+09:00",
      "dcterms:modified": "2018-02-14T11:59+09:00",
      "description": "HOME SPOT CUBE2 provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE2 contains improper authentication in WebUI.\r\n\r\nTaizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000138.html",
      "sec:cpe": {
        "#text": "cpe:/o:kddi:home_spot_cube_2_firmware",
        "@product": "HOME SPOT CUBE2 firmware",
        "@vendor": "KDDI",
        "@version": "2.2"
      },
      "sec:cvss": [
        {
          "@score": "3.3",
          "@severity": "Low",
          "@type": "Base",
          "@vector": "AV:A/AC:L/Au:N/C:N/I:P/A:N",
          "@version": "2.0"
        },
        {
          "@score": "6.5",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "@version": "3.0"
        }
      ],
      "sec:identifier": "JVNDB-2017-000138",
      "sec:references": [
        {
          "#text": "http://jvn.jp/en/jp/JVN24348065/index.html",
          "@id": "JVN#24348065",
          "@source": "JVN"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2186",
          "@id": "CVE-2017-2186",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2017-2186",
          "@id": "CVE-2017-2186",
          "@source": "NVD"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-264",
          "@title": "Permissions(CWE-264)"
        }
      ],
      "title": "HOME SPOT CUBE2 vulnerable to improper authentication in WebUI"
    }

    JVNDB-2017-000137

    Vulnerability from jvndb - Published: 2017-06-21 04:45 - Updated:2018-02-14 02:59
    Severity
    Summary
    HOME SPOT CUBE2 vulnerable to OS command injection in WebUI
    Details
    HOME SPOT CUBE2 provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE2 contains OS command injection in WebUI. Taizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000137.html",
      "dc:date": "2018-02-14T11:59+09:00",
      "dcterms:issued": "2017-06-21T13:45+09:00",
      "dcterms:modified": "2018-02-14T11:59+09:00",
      "description": "HOME SPOT CUBE2 provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE2 contains OS command injection in WebUI.\r\n\r\nTaizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000137.html",
      "sec:cpe": {
        "#text": "cpe:/o:kddi:home_spot_cube_2_firmware",
        "@product": "HOME SPOT CUBE2 firmware",
        "@vendor": "KDDI",
        "@version": "2.2"
      },
      "sec:cvss": [
        {
          "@score": "5.2",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "AV:A/AC:L/Au:S/C:P/I:P/A:P",
          "@version": "2.0"
        },
        {
          "@score": "6.8",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "@version": "3.0"
        }
      ],
      "sec:identifier": "JVNDB-2017-000137",
      "sec:references": [
        {
          "#text": "http://jvn.jp/en/jp/JVN24348065/index.html",
          "@id": "JVN#24348065",
          "@source": "JVN"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2185",
          "@id": "CVE-2017-2185",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2017-2185",
          "@id": "CVE-2017-2185",
          "@source": "NVD"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-78",
          "@title": "OS Command Injection(CWE-78)"
        }
      ],
      "title": "HOME SPOT CUBE2 vulnerable to OS command injection in WebUI"
    }

    JVNDB-2017-000136

    Vulnerability from jvndb - Published: 2017-06-21 04:44 - Updated:2018-02-14 02:59
    Severity
    Summary
    HOME SPOT CUBE2 vulnerable to buffer overflow in WebUI
    Details
    HOME SPOT CUBE2 provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE2 contains buffer overflow in WebUI. Taizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000136.html",
      "dc:date": "2018-02-14T11:59+09:00",
      "dcterms:issued": "2017-06-21T13:44+09:00",
      "dcterms:modified": "2018-02-14T11:59+09:00",
      "description": "HOME SPOT CUBE2 provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE2 contains buffer overflow in WebUI.\r\n\r\nTaizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000136.html",
      "sec:cpe": {
        "#text": "cpe:/o:kddi:home_spot_cube_2_firmware",
        "@product": "HOME SPOT CUBE2 firmware",
        "@vendor": "KDDI",
        "@version": "2.2"
      },
      "sec:cvss": [
        {
          "@score": "5.8",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "AV:A/AC:L/Au:N/C:P/I:P/A:P",
          "@version": "2.0"
        },
        {
          "@score": "8.8",
          "@severity": "High",
          "@type": "Base",
          "@vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "@version": "3.0"
        }
      ],
      "sec:identifier": "JVNDB-2017-000136",
      "sec:references": [
        {
          "#text": "http://jvn.jp/en/jp/JVN24348065/index.html",
          "@id": "JVN#24348065",
          "@source": "JVN"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2184",
          "@id": "CVE-2017-2184",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2017-2184",
          "@id": "CVE-2017-2184",
          "@source": "NVD"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-119",
          "@title": "Buffer Errors(CWE-119)"
        }
      ],
      "title": "HOME SPOT CUBE2 vulnerable to buffer overflow in WebUI"
    }

    JVNDB-2017-000135

    Vulnerability from jvndb - Published: 2017-06-21 04:44 - Updated:2018-02-14 02:54
    Severity
    Summary
    HOME SPOT CUBE2 vulnerable to OS command injection in clock settings
    Details
    HOME SPOT CUBE2 provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE2 contains OS command injection in clock settings. Taizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000135.html",
      "dc:date": "2018-02-14T11:54+09:00",
      "dcterms:issued": "2017-06-21T13:44+09:00",
      "dcterms:modified": "2018-02-14T11:54+09:00",
      "description": "HOME SPOT CUBE2 provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE2 contains OS command injection in clock settings.\r\n\r\nTaizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000135.html",
      "sec:cpe": {
        "#text": "cpe:/o:kddi:home_spot_cube_2_firmware",
        "@product": "HOME SPOT CUBE2 firmware",
        "@vendor": "KDDI",
        "@version": "2.2"
      },
      "sec:cvss": [
        {
          "@score": "5.2",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "AV:A/AC:L/Au:S/C:P/I:P/A:P",
          "@version": "2.0"
        },
        {
          "@score": "6.8",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "@version": "3.0"
        }
      ],
      "sec:identifier": "JVNDB-2017-000135",
      "sec:references": [
        {
          "#text": "http://jvn.jp/en/jp/JVN24348065/index.html",
          "@id": "JVN#24348065",
          "@source": "JVN"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2183",
          "@id": "CVE-2017-2183",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2017-2183",
          "@id": "CVE-2017-2183",
          "@source": "NVD"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-78",
          "@title": "OS Command Injection(CWE-78)"
        }
      ],
      "title": "HOME SPOT CUBE2 vulnerable to OS command injection in clock settings"
    }

    JVNDB-2016-000008

    Vulnerability from jvndb - Published: 2016-01-27 05:40 - Updated:2016-02-16 08:26
    Severity
    Summary
    HOME SPOT CUBE vulnerable to open redirect
    Details
    HOME SPOT CUBE provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE contains an open redirect vulnerability. Masaki Yoshikawa of LAC Co., Ltd. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000008.html",
      "dc:date": "2016-02-16T17:26+09:00",
      "dcterms:issued": "2016-01-27T14:40+09:00",
      "dcterms:modified": "2016-02-16T17:26+09:00",
      "description": "HOME SPOT CUBE provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE contains an open redirect vulnerability.\r\n\r\nMasaki Yoshikawa of LAC Co., Ltd. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000008.html",
      "sec:cpe": {
        "#text": "cpe:/h:kddi:home_spot_cube",
        "@product": "HOME SPOT CUBE",
        "@vendor": "KDDI",
        "@version": "2.2"
      },
      "sec:cvss": [
        {
          "@score": "2.6",
          "@severity": "Low",
          "@type": "Base",
          "@vector": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "@version": "2.0"
        },
        {
          "@score": "4.7",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N",
          "@version": "3.0"
        }
      ],
      "sec:identifier": "JVNDB-2016-000008",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN54686544/index.html",
          "@id": "JVN#54686544",
          "@source": "JVN"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1137",
          "@id": "CVE-2016-1137",
          "@source": "CVE"
        },
        {
          "#text": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-1137",
          "@id": "CVE-2016-1137",
          "@source": "NVD"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-20",
          "@title": "Improper Input Validation(CWE-20)"
        }
      ],
      "title": "HOME SPOT CUBE vulnerable to open redirect"
    }

    JVNDB-2016-000009

    Vulnerability from jvndb - Published: 2016-01-27 05:40 - Updated:2016-02-16 08:26
    Severity
    Summary
    HOME SPOT CUBE vulnerable to HTTP header injection
    Details
    HOME SPOT CUBE provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE contains a HTTP header injection vulnerability. Masaki Yoshikawa of LAC Co., Ltd. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000009.html",
      "dc:date": "2016-02-16T17:26+09:00",
      "dcterms:issued": "2016-01-27T14:40+09:00",
      "dcterms:modified": "2016-02-16T17:26+09:00",
      "description": "HOME SPOT CUBE provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE contains a HTTP header injection vulnerability.\r\n\r\nMasaki Yoshikawa of LAC Co., Ltd. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000009.html",
      "sec:cpe": {
        "#text": "cpe:/h:kddi:home_spot_cube",
        "@product": "HOME SPOT CUBE",
        "@vendor": "KDDI",
        "@version": "2.2"
      },
      "sec:cvss": [
        {
          "@score": "2.6",
          "@severity": "Low",
          "@type": "Base",
          "@vector": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "@version": "2.0"
        },
        {
          "@score": "4.7",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N",
          "@version": "3.0"
        }
      ],
      "sec:identifier": "JVNDB-2016-000009",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN54686544/index.html",
          "@id": "JVN#54686544",
          "@source": "JVN"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1138",
          "@id": "CVE-2016-1138",
          "@source": "CVE"
        },
        {
          "#text": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-1138",
          "@id": "CVE-2016-1138",
          "@source": "NVD"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "HOME SPOT CUBE vulnerable to HTTP header injection"
    }

    JVNDB-2016-000011

    Vulnerability from jvndb - Published: 2016-01-27 05:40 - Updated:2016-02-16 08:26
    Severity
    Summary
    HOME SPOT CUBE vulnerable to clickjacking
    Details
    HOME SPOT CUBE provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE contains a clickjacking vulnerabilitiy. Masaki Yoshikawa of LAC Co., Ltd. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000011.html",
      "dc:date": "2016-02-16T17:26+09:00",
      "dcterms:issued": "2016-01-27T14:40+09:00",
      "dcterms:modified": "2016-02-16T17:26+09:00",
      "description": "HOME SPOT CUBE provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE contains a clickjacking vulnerabilitiy.\r\n\r\nMasaki Yoshikawa of LAC Co., Ltd. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000011.html",
      "sec:cpe": {
        "#text": "cpe:/h:kddi:home_spot_cube",
        "@product": "HOME SPOT CUBE",
        "@vendor": "KDDI",
        "@version": "2.2"
      },
      "sec:cvss": [
        {
          "@score": "2.6",
          "@severity": "Low",
          "@type": "Base",
          "@vector": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "@version": "2.0"
        },
        {
          "@score": "4.3",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
          "@version": "3.0"
        }
      ],
      "sec:identifier": "JVNDB-2016-000011",
      "sec:references": [
        {
          "#text": "http://jvn.jp/en/jp/JVN54686544/index.html",
          "@id": "JVN#54686544",
          "@source": "JVN"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1140",
          "@id": "CVE-2016-1140",
          "@source": "CVE"
        },
        {
          "#text": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-1140",
          "@id": "CVE-2016-1140",
          "@source": "NVD"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "HOME SPOT CUBE vulnerable to clickjacking"
    }

    CVE-2024-29071 (GCVE-0-2024-29071)

    Vulnerability from nvd – Published: 2024-03-25 03:42 – Updated: 2025-03-28 07:38
    VLAI
    Summary
    HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change the system settings.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-04 13:53 UTC
    CWE
    • CWE-1391 - Use of weak credentials
    • CWE-522 - Insufficiently Protected Credentials
    Impacted products
    Vendor Product Version
    KDDI CORPORATION HGW BL1500HM Affected: Ver 002.001.013 and earlier
    Create a notification for this product.
    kddi hgw_bli500hm_firmware Affected: 0 , ≤ 002.001.013 (custom)
        cpe:2.3:o:kddi:hgw_bli500hm_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:kddi:hgw_bli500hm_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "hgw_bli500hm_firmware",
                "vendor": "kddi",
                "versions": [
                  {
                    "lessThanOrEqual": "002.001.013",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "ADJACENT_NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-29071",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-04T13:53:58.969525Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-522",
                    "description": "CWE-522 Insufficiently Protected Credentials",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-04T13:55:29.279Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T01:03:51.863Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.au.com/support/service/internet/guide/modem/bl1500hm/firmware/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU93546510/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "HGW BL1500HM",
              "vendor": "KDDI CORPORATION",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver 002.001.013 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change the system settings."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1391",
                  "description": "Use of weak credentials",
                  "lang": "en-US",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-03-28T07:38:42.105Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://kddi-tech.com/contents/appendix_L2_06.html#20304f4c-af1b-49fd-c3b5-8d1f55fd8b4f"
            },
            {
              "url": "https://jvn.jp/en/vu/JVNVU93546510/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2024-29071",
        "datePublished": "2024-03-25T03:42:31.070Z",
        "dateReserved": "2024-03-18T01:23:31.527Z",
        "dateUpdated": "2025-03-28T07:38:42.105Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-28041 (GCVE-0-2024-28041)

    Vulnerability from nvd – Published: 2024-03-25 03:42 – Updated: 2025-03-28 07:39
    VLAI
    Summary
    HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary command.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-17 15:30 UTC
    CWE
    • Arbitrary command execution
    • CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
    Impacted products
    Vendor Product Version
    KDDI CORPORATION HGW BL1500HM Affected: Ver 002.001.013 and earlier
    Create a notification for this product.
    kddi hgw_bli500hm_firmware Affected: 0 , ≤ 002.001.013 (custom)
        cpe:2.3:o:kddi:hgw_bli500hm_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:kddi:hgw_bli500hm_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "hgw_bli500hm_firmware",
                "vendor": "kddi",
                "versions": [
                  {
                    "lessThanOrEqual": "002.001.013",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "ADJACENT_NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-28041",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-17T15:30:23.593154Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-77",
                    "description": "CWE-77 Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-17T15:32:08.389Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:48:47.724Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.au.com/support/service/internet/guide/modem/bl1500hm/firmware/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU93546510/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "HGW BL1500HM",
              "vendor": "KDDI CORPORATION",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver 002.001.013 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary command."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Arbitrary command execution",
                  "lang": "en-US",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-03-28T07:39:02.488Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://kddi-tech.com/contents/appendix_L2_06.html#20304f4c-af1b-49fd-c3b5-8d1f55fd8b4f"
            },
            {
              "url": "https://jvn.jp/en/vu/JVNVU93546510/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2024-28041",
        "datePublished": "2024-03-25T03:42:17.754Z",
        "dateReserved": "2024-03-18T01:23:33.325Z",
        "dateUpdated": "2025-03-28T07:39:02.488Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-43543 (GCVE-0-2022-43543)

    Vulnerability from nvd – Published: 2022-12-21 00:00 – Updated: 2025-04-16 17:36
    VLAI
    Summary
    KDDI +Message App, NTT DOCOMO +Message App, and SoftBank +Message App contain a vulnerability caused by improper handling of Unicode control characters. +Message App displays text unprocessed, even when control characters are contained, and the text is shown based on Unicode control character's specifications. Therefore, a crafted text may display misleading web links. As a result, a spoofed URL may be displayed and phishing attacks may be conducted. Affected products and versions are as follows: KDDI +Message App for Android prior to version 3.9.2 and +Message App for iOS prior to version 3.9.4, NTT DOCOMO +Message App for Android prior to version 54.49.0500 and +Message App for iOS prior to version 3.9.4, and SoftBank +Message App for Android prior to version 12.9.5 and +Message App for iOS prior to version 3.9.4
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-16 17:36 UTC
    CWE
    • User Interface (UI) Misrepresentation of Critical Information
    • CWE-116 - Improper Encoding or Escaping of Output
    Impacted products
    Vendor Product Version
    KDDI CORPORATION, NTT DOCOMO, INC., and SoftBank Corp. KDDI +Message App for Android and for iOS, NTT DOCOMO +Message App for Android and for iOS, and SoftBank +Message App for Android and for iOS Affected: KDDI +Message App for Android prior to version 3.9.2 and +Message App for iOS prior to version 3.9.4, NTT DOCOMO +Message App for Android prior to version 54.49.0500 and +Message App for iOS prior to version 3.9.4, and SoftBank +Message App for Android prior to version 12.9.5 and +Message App for iOS prior to version 3.9.4
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T13:32:59.662Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.au.com/mobile/service/plus-message/information/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.docomo.ne.jp/service/plus_message/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.softbank.jp/mobile/service/plus-message/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/jp/JVN43561812/index.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 5.4,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "LOW",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-43543",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-16T17:36:38.691998Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-116",
                    "description": "CWE-116 Improper Encoding or Escaping of Output",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-16T17:36:43.679Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "KDDI +Message App for Android and for iOS, NTT DOCOMO +Message App for Android and for iOS, and SoftBank +Message App for Android and for iOS",
              "vendor": "KDDI CORPORATION, NTT DOCOMO, INC., and SoftBank Corp.",
              "versions": [
                {
                  "status": "affected",
                  "version": "KDDI +Message App for Android prior to version 3.9.2 and +Message App for iOS prior to version 3.9.4, NTT DOCOMO +Message App for Android prior to version 54.49.0500 and +Message App for iOS prior to version 3.9.4, and SoftBank +Message App for Android prior to version 12.9.5 and +Message App for iOS prior to version 3.9.4"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "KDDI +Message App, NTT DOCOMO +Message App, and SoftBank +Message App contain a vulnerability caused by improper handling of Unicode control characters. +Message App displays text unprocessed, even when control characters are contained, and the text is shown based on Unicode control character\u0027s specifications. Therefore, a crafted text may display misleading web links. As a result, a spoofed URL may be displayed and phishing attacks may be conducted. Affected products and versions are as follows: KDDI +Message App for Android prior to version 3.9.2 and +Message App for iOS prior to version 3.9.4, NTT DOCOMO +Message App for Android prior to version 54.49.0500 and +Message App for iOS prior to version 3.9.4, and SoftBank +Message App for Android prior to version 12.9.5 and +Message App for iOS prior to version 3.9.4"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "User Interface (UI) Misrepresentation of Critical Information",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-12-21T00:00:00.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://www.au.com/mobile/service/plus-message/information/"
            },
            {
              "url": "https://www.docomo.ne.jp/service/plus_message/"
            },
            {
              "url": "https://www.softbank.jp/mobile/service/plus-message/"
            },
            {
              "url": "https://jvn.jp/en/jp/JVN43561812/index.html"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2022-43543",
        "datePublished": "2022-12-21T00:00:00.000Z",
        "dateReserved": "2022-12-14T00:00:00.000Z",
        "dateUpdated": "2025-04-16T17:36:43.679Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-0691 (GCVE-0-2018-0691)

    Vulnerability from nvd – Published: 2018-11-15 15:00 – Updated: 2024-08-05 03:35
    VLAI
    Summary
    Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23) do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
    Severity
    No CVSS data available.
    CWE
    • Fails to verify SSL certificates
    Impacted products
    Vendor Product Version
    Softbank, NTT docomo, KDDI Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23) Affected: Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23
    Create a notification for this product.
    Date Public
    2018-11-15 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T03:35:49.057Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.au.com/information/notice_mobile/service/2018-002/"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.softbank.jp/mobile/info/personal/news/service/20180927a/"
              },
              {
                "name": "JVN#37288228",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_JVN",
                  "x_transferred"
                ],
                "url": "http://jvn.jp/en/jp/JVN37288228/index.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.nttdocomo.co.jp/info/notice/page/180927_00.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23)",
              "vendor": "Softbank, NTT docomo, KDDI",
              "versions": [
                {
                  "status": "affected",
                  "version": "Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23"
                }
              ]
            }
          ],
          "datePublic": "2018-11-15T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23) do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Fails to verify SSL certificates",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-11-15T14:57:01.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.au.com/information/notice_mobile/service/2018-002/"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.softbank.jp/mobile/info/personal/news/service/20180927a/"
            },
            {
              "name": "JVN#37288228",
              "tags": [
                "third-party-advisory",
                "x_refsource_JVN"
              ],
              "url": "http://jvn.jp/en/jp/JVN37288228/index.html"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.nttdocomo.co.jp/info/notice/page/180927_00.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2018-0691",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23)",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Softbank, NTT docomo, KDDI"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23) do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Fails to verify SSL certificates"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://www.au.com/information/notice_mobile/service/2018-002/",
                  "refsource": "MISC",
                  "url": "https://www.au.com/information/notice_mobile/service/2018-002/"
                },
                {
                  "name": "https://www.softbank.jp/mobile/info/personal/news/service/20180927a/",
                  "refsource": "MISC",
                  "url": "https://www.softbank.jp/mobile/info/personal/news/service/20180927a/"
                },
                {
                  "name": "JVN#37288228",
                  "refsource": "JVN",
                  "url": "http://jvn.jp/en/jp/JVN37288228/index.html"
                },
                {
                  "name": "https://www.nttdocomo.co.jp/info/notice/page/180927_00.html",
                  "refsource": "MISC",
                  "url": "https://www.nttdocomo.co.jp/info/notice/page/180927_00.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2018-0691",
        "datePublished": "2018-11-15T15:00:00.000Z",
        "dateReserved": "2017-11-27T00:00:00.000Z",
        "dateUpdated": "2024-08-05T03:35:49.057Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-0517 (GCVE-0-2018-0517)

    Vulnerability from nvd – Published: 2018-02-08 14:00 – Updated: 2024-08-05 03:28
    VLAI
    Summary
    Untrusted search path vulnerability in Anshin net security for Windows Version 16.0.1.44 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
    Severity
    No CVSS data available.
    CWE
    • Untrusted search path vulnerability
    References
    URL Tags
    https://jvn.jp/en/jp/JVN70615027/index.html third-party-advisoryx_refsource_JVN
    Impacted products
    Vendor Product Version
    KDDI CORPORATION Anshin net security for Windows Affected: Version 16.0.1.44 and earlier
    Create a notification for this product.
    Date Public
    2018-02-06 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T03:28:11.086Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "JVN#70615027",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_JVN",
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/jp/JVN70615027/index.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Anshin net security for Windows",
              "vendor": "KDDI CORPORATION",
              "versions": [
                {
                  "status": "affected",
                  "version": "Version 16.0.1.44 and earlier"
                }
              ]
            }
          ],
          "datePublic": "2018-02-06T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Untrusted search path vulnerability in Anshin net security for Windows Version 16.0.1.44 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Untrusted search path vulnerability",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-02-08T13:57:01.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "name": "JVN#70615027",
              "tags": [
                "third-party-advisory",
                "x_refsource_JVN"
              ],
              "url": "https://jvn.jp/en/jp/JVN70615027/index.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2018-0517",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Anshin net security for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Version 16.0.1.44 and earlier"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "KDDI CORPORATION"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Untrusted search path vulnerability in Anshin net security for Windows Version 16.0.1.44 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Untrusted search path vulnerability"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "JVN#70615027",
                  "refsource": "JVN",
                  "url": "https://jvn.jp/en/jp/JVN70615027/index.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2018-0517",
        "datePublished": "2018-02-08T14:00:00.000Z",
        "dateReserved": "2017-11-27T00:00:00.000Z",
        "dateUpdated": "2024-08-05T03:28:11.086Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-29071 (GCVE-0-2024-29071)

    Vulnerability from cvelistv5 – Published: 2024-03-25 03:42 – Updated: 2025-03-28 07:38
    VLAI
    Summary
    HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change the system settings.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-04 13:53 UTC
    CWE
    • CWE-1391 - Use of weak credentials
    • CWE-522 - Insufficiently Protected Credentials
    Impacted products
    Vendor Product Version
    KDDI CORPORATION HGW BL1500HM Affected: Ver 002.001.013 and earlier
    Create a notification for this product.
    kddi hgw_bli500hm_firmware Affected: 0 , ≤ 002.001.013 (custom)
        cpe:2.3:o:kddi:hgw_bli500hm_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:kddi:hgw_bli500hm_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "hgw_bli500hm_firmware",
                "vendor": "kddi",
                "versions": [
                  {
                    "lessThanOrEqual": "002.001.013",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "ADJACENT_NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-29071",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-04T13:53:58.969525Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-522",
                    "description": "CWE-522 Insufficiently Protected Credentials",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-04T13:55:29.279Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T01:03:51.863Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.au.com/support/service/internet/guide/modem/bl1500hm/firmware/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU93546510/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "HGW BL1500HM",
              "vendor": "KDDI CORPORATION",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver 002.001.013 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change the system settings."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1391",
                  "description": "Use of weak credentials",
                  "lang": "en-US",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-03-28T07:38:42.105Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://kddi-tech.com/contents/appendix_L2_06.html#20304f4c-af1b-49fd-c3b5-8d1f55fd8b4f"
            },
            {
              "url": "https://jvn.jp/en/vu/JVNVU93546510/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2024-29071",
        "datePublished": "2024-03-25T03:42:31.070Z",
        "dateReserved": "2024-03-18T01:23:31.527Z",
        "dateUpdated": "2025-03-28T07:38:42.105Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-28041 (GCVE-0-2024-28041)

    Vulnerability from cvelistv5 – Published: 2024-03-25 03:42 – Updated: 2025-03-28 07:39
    VLAI
    Summary
    HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary command.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-17 15:30 UTC
    CWE
    • Arbitrary command execution
    • CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
    Impacted products
    Vendor Product Version
    KDDI CORPORATION HGW BL1500HM Affected: Ver 002.001.013 and earlier
    Create a notification for this product.
    kddi hgw_bli500hm_firmware Affected: 0 , ≤ 002.001.013 (custom)
        cpe:2.3:o:kddi:hgw_bli500hm_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:kddi:hgw_bli500hm_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "hgw_bli500hm_firmware",
                "vendor": "kddi",
                "versions": [
                  {
                    "lessThanOrEqual": "002.001.013",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "ADJACENT_NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-28041",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-17T15:30:23.593154Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-77",
                    "description": "CWE-77 Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-17T15:32:08.389Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:48:47.724Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.au.com/support/service/internet/guide/modem/bl1500hm/firmware/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU93546510/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "HGW BL1500HM",
              "vendor": "KDDI CORPORATION",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver 002.001.013 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary command."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Arbitrary command execution",
                  "lang": "en-US",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-03-28T07:39:02.488Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://kddi-tech.com/contents/appendix_L2_06.html#20304f4c-af1b-49fd-c3b5-8d1f55fd8b4f"
            },
            {
              "url": "https://jvn.jp/en/vu/JVNVU93546510/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2024-28041",
        "datePublished": "2024-03-25T03:42:17.754Z",
        "dateReserved": "2024-03-18T01:23:33.325Z",
        "dateUpdated": "2025-03-28T07:39:02.488Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-43543 (GCVE-0-2022-43543)

    Vulnerability from cvelistv5 – Published: 2022-12-21 00:00 – Updated: 2025-04-16 17:36
    VLAI
    Summary
    KDDI +Message App, NTT DOCOMO +Message App, and SoftBank +Message App contain a vulnerability caused by improper handling of Unicode control characters. +Message App displays text unprocessed, even when control characters are contained, and the text is shown based on Unicode control character's specifications. Therefore, a crafted text may display misleading web links. As a result, a spoofed URL may be displayed and phishing attacks may be conducted. Affected products and versions are as follows: KDDI +Message App for Android prior to version 3.9.2 and +Message App for iOS prior to version 3.9.4, NTT DOCOMO +Message App for Android prior to version 54.49.0500 and +Message App for iOS prior to version 3.9.4, and SoftBank +Message App for Android prior to version 12.9.5 and +Message App for iOS prior to version 3.9.4
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-16 17:36 UTC
    CWE
    • User Interface (UI) Misrepresentation of Critical Information
    • CWE-116 - Improper Encoding or Escaping of Output
    Impacted products
    Vendor Product Version
    KDDI CORPORATION, NTT DOCOMO, INC., and SoftBank Corp. KDDI +Message App for Android and for iOS, NTT DOCOMO +Message App for Android and for iOS, and SoftBank +Message App for Android and for iOS Affected: KDDI +Message App for Android prior to version 3.9.2 and +Message App for iOS prior to version 3.9.4, NTT DOCOMO +Message App for Android prior to version 54.49.0500 and +Message App for iOS prior to version 3.9.4, and SoftBank +Message App for Android prior to version 12.9.5 and +Message App for iOS prior to version 3.9.4
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T13:32:59.662Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.au.com/mobile/service/plus-message/information/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.docomo.ne.jp/service/plus_message/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.softbank.jp/mobile/service/plus-message/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/jp/JVN43561812/index.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 5.4,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "LOW",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-43543",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-16T17:36:38.691998Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-116",
                    "description": "CWE-116 Improper Encoding or Escaping of Output",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-16T17:36:43.679Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "KDDI +Message App for Android and for iOS, NTT DOCOMO +Message App for Android and for iOS, and SoftBank +Message App for Android and for iOS",
              "vendor": "KDDI CORPORATION, NTT DOCOMO, INC., and SoftBank Corp.",
              "versions": [
                {
                  "status": "affected",
                  "version": "KDDI +Message App for Android prior to version 3.9.2 and +Message App for iOS prior to version 3.9.4, NTT DOCOMO +Message App for Android prior to version 54.49.0500 and +Message App for iOS prior to version 3.9.4, and SoftBank +Message App for Android prior to version 12.9.5 and +Message App for iOS prior to version 3.9.4"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "KDDI +Message App, NTT DOCOMO +Message App, and SoftBank +Message App contain a vulnerability caused by improper handling of Unicode control characters. +Message App displays text unprocessed, even when control characters are contained, and the text is shown based on Unicode control character\u0027s specifications. Therefore, a crafted text may display misleading web links. As a result, a spoofed URL may be displayed and phishing attacks may be conducted. Affected products and versions are as follows: KDDI +Message App for Android prior to version 3.9.2 and +Message App for iOS prior to version 3.9.4, NTT DOCOMO +Message App for Android prior to version 54.49.0500 and +Message App for iOS prior to version 3.9.4, and SoftBank +Message App for Android prior to version 12.9.5 and +Message App for iOS prior to version 3.9.4"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "User Interface (UI) Misrepresentation of Critical Information",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-12-21T00:00:00.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://www.au.com/mobile/service/plus-message/information/"
            },
            {
              "url": "https://www.docomo.ne.jp/service/plus_message/"
            },
            {
              "url": "https://www.softbank.jp/mobile/service/plus-message/"
            },
            {
              "url": "https://jvn.jp/en/jp/JVN43561812/index.html"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2022-43543",
        "datePublished": "2022-12-21T00:00:00.000Z",
        "dateReserved": "2022-12-14T00:00:00.000Z",
        "dateUpdated": "2025-04-16T17:36:43.679Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-0691 (GCVE-0-2018-0691)

    Vulnerability from cvelistv5 – Published: 2018-11-15 15:00 – Updated: 2024-08-05 03:35
    VLAI
    Summary
    Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23) do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
    Severity
    No CVSS data available.
    CWE
    • Fails to verify SSL certificates
    Impacted products
    Vendor Product Version
    Softbank, NTT docomo, KDDI Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23) Affected: Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23
    Create a notification for this product.
    Date Public
    2018-11-15 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T03:35:49.057Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.au.com/information/notice_mobile/service/2018-002/"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.softbank.jp/mobile/info/personal/news/service/20180927a/"
              },
              {
                "name": "JVN#37288228",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_JVN",
                  "x_transferred"
                ],
                "url": "http://jvn.jp/en/jp/JVN37288228/index.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.nttdocomo.co.jp/info/notice/page/180927_00.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23)",
              "vendor": "Softbank, NTT docomo, KDDI",
              "versions": [
                {
                  "status": "affected",
                  "version": "Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23"
                }
              ]
            }
          ],
          "datePublic": "2018-11-15T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23) do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Fails to verify SSL certificates",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-11-15T14:57:01.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.au.com/information/notice_mobile/service/2018-002/"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.softbank.jp/mobile/info/personal/news/service/20180927a/"
            },
            {
              "name": "JVN#37288228",
              "tags": [
                "third-party-advisory",
                "x_refsource_JVN"
              ],
              "url": "http://jvn.jp/en/jp/JVN37288228/index.html"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.nttdocomo.co.jp/info/notice/page/180927_00.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2018-0691",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23)",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Softbank, NTT docomo, KDDI"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23) do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Fails to verify SSL certificates"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://www.au.com/information/notice_mobile/service/2018-002/",
                  "refsource": "MISC",
                  "url": "https://www.au.com/information/notice_mobile/service/2018-002/"
                },
                {
                  "name": "https://www.softbank.jp/mobile/info/personal/news/service/20180927a/",
                  "refsource": "MISC",
                  "url": "https://www.softbank.jp/mobile/info/personal/news/service/20180927a/"
                },
                {
                  "name": "JVN#37288228",
                  "refsource": "JVN",
                  "url": "http://jvn.jp/en/jp/JVN37288228/index.html"
                },
                {
                  "name": "https://www.nttdocomo.co.jp/info/notice/page/180927_00.html",
                  "refsource": "MISC",
                  "url": "https://www.nttdocomo.co.jp/info/notice/page/180927_00.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2018-0691",
        "datePublished": "2018-11-15T15:00:00.000Z",
        "dateReserved": "2017-11-27T00:00:00.000Z",
        "dateUpdated": "2024-08-05T03:35:49.057Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-0517 (GCVE-0-2018-0517)

    Vulnerability from cvelistv5 – Published: 2018-02-08 14:00 – Updated: 2024-08-05 03:28
    VLAI
    Summary
    Untrusted search path vulnerability in Anshin net security for Windows Version 16.0.1.44 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
    Severity
    No CVSS data available.
    CWE
    • Untrusted search path vulnerability
    References
    URL Tags
    https://jvn.jp/en/jp/JVN70615027/index.html third-party-advisoryx_refsource_JVN
    Impacted products
    Vendor Product Version
    KDDI CORPORATION Anshin net security for Windows Affected: Version 16.0.1.44 and earlier
    Create a notification for this product.
    Date Public
    2018-02-06 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T03:28:11.086Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "JVN#70615027",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_JVN",
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/jp/JVN70615027/index.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Anshin net security for Windows",
              "vendor": "KDDI CORPORATION",
              "versions": [
                {
                  "status": "affected",
                  "version": "Version 16.0.1.44 and earlier"
                }
              ]
            }
          ],
          "datePublic": "2018-02-06T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Untrusted search path vulnerability in Anshin net security for Windows Version 16.0.1.44 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Untrusted search path vulnerability",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-02-08T13:57:01.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "name": "JVN#70615027",
              "tags": [
                "third-party-advisory",
                "x_refsource_JVN"
              ],
              "url": "https://jvn.jp/en/jp/JVN70615027/index.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2018-0517",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Anshin net security for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Version 16.0.1.44 and earlier"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "KDDI CORPORATION"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Untrusted search path vulnerability in Anshin net security for Windows Version 16.0.1.44 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Untrusted search path vulnerability"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "JVN#70615027",
                  "refsource": "JVN",
                  "url": "https://jvn.jp/en/jp/JVN70615027/index.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2018-0517",
        "datePublished": "2018-02-08T14:00:00.000Z",
        "dateReserved": "2017-11-27T00:00:00.000Z",
        "dateUpdated": "2024-08-05T03:28:11.086Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }