Search
Find a vulnerability
Search criteria
38 vulnerabilities by kddi
JVNDB-2026-000069
Vulnerability from jvndb - Published: 2026-05-13 06:41 - Updated:2026-05-13 06:41
Severity
Summary
Android App "Anshin Filter for au" vulnerable to cleartext transmission of sensitive information
Details
References
| Type | URL | |
|---|---|---|
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-000069.html",
"dc:date": "2026-05-13T15:41+09:00",
"dcterms:issued": "2026-05-13T15:41+09:00",
"dcterms:modified": "2026-05-13T15:41+09:00",
"description": "Android App \"Anshin Filter for au\" provided by KDDI CORPORATION contains the following vulnerability.\u003ca href=\u0027https://cwe.mitre.org/data/definitions/319.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003cul\u003e\u003cli\u003eCleartext transmission of sensitive information (CWE-319) - CVE-2026-41281\u003c/li\u003e\u003c/ul\u003e",
"link": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-000069.html",
"sec:cpe": {
"#text": "cpe:/a:kddi:anshin_filter_for_au_for_android",
"@product": "Android App \"Anshin Filter for au\"",
"@vendor": "KDDI",
"@version": "2.2"
},
"sec:cvss": {
"@score": "4.8",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2026-000069",
"sec:references": [
{
"#text": "https://jvn.jp/en/jp/JVN24167657/index.html",
"@id": "JVN#24167657",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-41281",
"@id": "CVE-2026-41281",
"@source": "CVE"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-Other",
"@title": "No Mapping(CWE-Other)"
}
],
"title": "Android App \"Anshin Filter for au\" vulnerable to cleartext transmission of sensitive information"
}
JVNDB-2026-000043
Vulnerability from jvndb - Published: 2026-03-25 09:41 - Updated:2026-03-25 09:41
Severity
Summary
SHARP routers missing authentication for some web APIs
Details
SHARP routers do not perform authentication for some web APIs.
Those web APIs provide device information, and the initial administrative password is based on a part of the device information.
- Missing authentication for critical function (CWE-306) - CVE-2026-32326
References
| Type | URL | |
|---|---|---|
Impacted products
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-000043.html",
"dc:date": "2026-03-25T18:41+09:00",
"dcterms:issued": "2026-03-25T18:41+09:00",
"dcterms:modified": "2026-03-25T18:41+09:00",
"description": "SHARP routers do not perform authentication for some web APIs.\r\nThose web APIs provide device information, and the initial administrative password is based on a part of the device information.\u003ca href=\u0027https://cwe.mitre.org/data/definitions/306.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003cul\u003e\u003cli\u003eMissing authentication for critical function (CWE-306) - CVE-2026-32326\u003c/li\u003e\u003c/ul\u003eShota Zaizen reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-000043.html",
"sec:cpe": [
{
"#text": "cpe:/o:kddi:speed_wi-fi_5g_x01",
"@product": "Speed Wi-Fi 5G X01",
"@vendor": "KDDI",
"@version": "2.2"
},
{
"#text": "cpe:/o:nttdocomo:home_5g_hr01",
"@product": "home 5G HR01",
"@vendor": "NTT DOCOMO, INC.",
"@version": "2.2"
},
{
"#text": "cpe:/o:nttdocomo:home_5g_hr02",
"@product": "home 5G HR02",
"@vendor": "NTT DOCOMO, INC.",
"@version": "2.2"
},
{
"#text": "cpe:/o:nttdocomo:wi-fi_station_sh-52a_firmware",
"@product": "Wi-Fi STATION SH-52A",
"@vendor": "NTT DOCOMO, INC.",
"@version": "2.2"
},
{
"#text": "cpe:/o:nttdocomo:wi-fi_station_sh-52b_firmware",
"@product": "Wi-Fi STATION SH-52B",
"@vendor": "NTT DOCOMO, INC.",
"@version": "2.2"
},
{
"#text": "cpe:/o:nttdocomo:wi-fi_station_sh-54c_firmware",
"@product": "Wi-Fi STATION SH-54C",
"@vendor": "NTT DOCOMO, INC.",
"@version": "2.2"
},
{
"#text": "cpe:/o:softbank:5gmobile_wi-fi_router_sh-u01",
"@product": "5G Mobile Router SH-U01",
"@vendor": "SoftBank",
"@version": "2.2"
},
{
"#text": "cpe:/o:softbank:pocket_wifi_5g_a503sh",
"@product": "Pocket WiFi 5G A503SH versions",
"@vendor": "SoftBank",
"@version": "2.2"
}
],
"sec:cvss": {
"@score": "5.7",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2026-000043",
"sec:references": [
{
"#text": "https://jvn.jp/en/jp/JVN49524110/index.html",
"@id": "JVN#49524110",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-32326",
"@id": "CVE-2026-32326",
"@source": "CVE"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-Other",
"@title": "No Mapping(CWE-Other)"
}
],
"title": "SHARP routers missing authentication for some web APIs"
}
JVNDB-2025-000097
Vulnerability from jvndb - Published: 2025-11-17 05:09 - Updated:2025-11-17 05:09
Severity
Summary
"Dejira" App for iOS vulnerable to improper server certificate verification
Details
"Dejira" App for iOS provided by KDDI CORPORATION contains the following vulnerability.
- Improper server certificate verification (CWE-295)
References
| Type | URL | |
|---|---|---|
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-000097.html",
"dc:date": "2025-11-17T14:09+09:00",
"dcterms:issued": "2025-11-17T14:09+09:00",
"dcterms:modified": "2025-11-17T14:09+09:00",
"description": "\"Dejira\" App for iOS provided by KDDI CORPORATION contains the following vulnerability.\r\n\u003cul\u003e\u003cli\u003eImproper server certificate verification (CWE-295)\u003c/li\u003e\u003c/ul\u003e\r\nTsuyoshi Ogawa of SIE Co.,Ltd reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-000097.html",
"sec:cpe": {
"#text": "cpe:/a:kddi:dejira_app",
"@product": "\"Dejira\" App for iOS",
"@vendor": "KDDI",
"@version": "2.2"
},
"sec:cvss": {
"@score": "4.8",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2025-000097",
"sec:references": [
{
"#text": "https://jvn.jp/en/jp/JVN54005037/index.html",
"@id": "JVN#54005037",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2025-60022",
"@id": "CVE-2025-60022",
"@source": "CVE"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-Other",
"@title": "No Mapping(CWE-Other)"
}
],
"title": "\"Dejira\" App for iOS vulnerable to improper server certificate verification"
}
JVNDB-2025-000018
Vulnerability from jvndb - Published: 2025-03-19 06:33 - Updated:2025-03-28 02:48
Severity
Summary
Multiple vulnerabilities in home gateway HGW-BL1500HM
Details
Home gateway HGW-BL1500HM provided by KDDI CORPORATION contains multiple vulnerabilities listed below.
- Stored cross-site scripting in the NickName registration screen (CWE-79) - CVE-2025-27567
- Stored cross-site scripting in the USB storage file-sharing function (CWE-79) - CVE-2025-27574
- Path traversal in the file/folder listing process of the USB storage file-sharing function (CWE-22) - CVE-2025-27716
- Path traversal in the file upload process of the USB storage file-sharing function (CWE-22) - CVE-2025-27718
- Path traversal in the file download process of the USB storage file-sharing function (CWE-22) - CVE-2025-27726
- Path traversal in the file deletion process of the USB storage file-sharing function (CWE-22) - CVE-2025-27932
References
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-000018.html",
"dc:date": "2025-03-28T11:48+09:00",
"dcterms:issued": "2025-03-19T15:33+09:00",
"dcterms:modified": "2025-03-28T11:48+09:00",
"description": "Home gateway HGW-BL1500HM provided by KDDI CORPORATION contains multiple vulnerabilities listed below.\r\n\u003cul\u003e\u003cli\u003eStored cross-site scripting in the NickName registration screen (CWE-79) - CVE-2025-27567\u003c/li\u003e\u003cli\u003eStored cross-site scripting in the USB storage file-sharing function (CWE-79) - CVE-2025-27574\u003c/li\u003e\u003cli\u003ePath traversal in the file/folder listing process of the USB storage file-sharing function (CWE-22) - CVE-2025-27716\u003c/li\u003e\u003cli\u003ePath traversal in the file upload process of the USB storage file-sharing function (CWE-22) - CVE-2025-27718\u003c/li\u003e\u003cli\u003ePath traversal in the file download process of the USB storage file-sharing function (CWE-22) - CVE-2025-27726\u003c/li\u003e\u003cli\u003ePath traversal in the file deletion process of the USB storage file-sharing function (CWE-22) - CVE-2025-27932\u003c/li\u003e\u003c/ul\u003e\r\nHuiseong Seo reported these vulnerabilities to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-000018.html",
"sec:cpe": {
"#text": "cpe:/o:kddi:hgw-bl1500hm",
"@product": "HGW-BL1500HM",
"@vendor": "KDDI",
"@version": "2.2"
},
"sec:cvss": {
"@score": "8.8",
"@severity": "High",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2025-000018",
"sec:references": [
{
"#text": "https://jvn.jp/en/jp/JVN04278547/index.html",
"@id": "JVN#04278547",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2025-27567",
"@id": "CVE-2025-27567",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2025-27574",
"@id": "CVE-2025-27574",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2025-27716",
"@id": "CVE-2025-27716",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2025-27718",
"@id": "CVE-2025-27718",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2025-27726",
"@id": "CVE-2025-27726",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2025-27932",
"@id": "CVE-2025-27932",
"@source": "CVE"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-22",
"@title": "Path Traversal(CWE-22)"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-79",
"@title": "Cross-site Scripting(CWE-79)"
}
],
"title": "Multiple vulnerabilities in home gateway HGW-BL1500HM"
}
JVNDB-2024-000123
Vulnerability from jvndb - Published: 2024-11-29 06:30 - Updated:2024-11-29 06:30
Severity
Summary
Multiple FCNT Android devices vulnerable to authentication bypass
Details
Multiple FCNT Android devices provide security features such as "privacy mode" where arbitrary applications can be set not to be displayed, etc.
The devices contain an authentication bypass vulnerability (CWE-306), where, under certain conditions, the setting pages may be accessed without authentication.
References
| Type | URL | |
|---|---|---|
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2024/JVNDB-2024-000123.html",
"dc:date": "2024-11-29T15:30+09:00",
"dcterms:issued": "2024-11-29T15:30+09:00",
"dcterms:modified": "2024-11-29T15:30+09:00",
"description": "Multiple FCNT Android devices provide security features such as \"privacy mode\" where arbitrary applications can be set not to be displayed, etc.\r\nThe devices contain an authentication bypass vulnerability (CWE-306), where, under certain conditions, the setting pages may be accessed without authentication.",
"link": "https://jvndb.jvn.jp/en/contents/2024/JVNDB-2024-000123.html",
"sec:cpe": [
{
"#text": "cpe:/o:kddi:arrows",
"@product": "arrows",
"@vendor": "KDDI",
"@version": "2.2"
},
{
"#text": "cpe:/o:nttdocomo:arrows",
"@product": "arrows",
"@vendor": "NTT DOCOMO, INC.",
"@version": "2.2"
},
{
"#text": "cpe:/o:nttdocomo:arrows",
"@product": "arrows",
"@vendor": "NTT DOCOMO, INC.",
"@version": "2.2"
},
{
"#text": "cpe:/o:softbank:arrows",
"@product": "arrows",
"@vendor": "SoftBank",
"@version": "2.2"
}
],
"sec:cvss": {
"@score": "3.1",
"@severity": "Low",
"@type": "Base",
"@vector": "CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2024-000123",
"sec:references": [
{
"#text": "https://jvn.jp/en/jp/JVN43845108/index.html",
"@id": "JVN#43845108",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2024-53701",
"@id": "CVE-2024-53701",
"@source": "CVE"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-Other",
"@title": "No Mapping(CWE-Other)"
}
],
"title": "Multiple FCNT Android devices vulnerable to authentication bypass"
}
JVNDB-2024-003016
Vulnerability from jvndb - Published: 2024-03-25 08:28 - Updated:2025-03-28 03:01
Severity
Summary
Multiple vulnerabilities in home gateway HGW BL1500HM
Details
Home gateway HGW BL1500HM provided by KDDI CORPORATION contains multiple vulnerabilities listed below.
* Use of weak credentials (CWE-1391) - CVE-2024-21865, CVE-2024-29071
* Command injection (CWE-77) - CVE-2024-28041
Chuya Hayakawa of 00One, Inc. reported these vulnerabilities to JPCERT/CC.
JPCERT/CC coordinated with the developer.
References
| Type | URL | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2024/JVNDB-2024-003016.html",
"dc:date": "2025-03-28T12:01+09:00",
"dcterms:issued": "2024-03-25T17:28+09:00",
"dcterms:modified": "2025-03-28T12:01+09:00",
"description": "Home gateway HGW BL1500HM provided by KDDI CORPORATION contains multiple vulnerabilities listed below.\r\n\r\n * Use of weak credentials (CWE-1391) - CVE-2024-21865, CVE-2024-29071\r\n * Command injection (CWE-77) - CVE-2024-28041\r\n\r\nChuya Hayakawa of 00One, Inc. reported these vulnerabilities to JPCERT/CC.\r\nJPCERT/CC coordinated with the developer.",
"link": "https://jvndb.jvn.jp/en/contents/2024/JVNDB-2024-003016.html",
"sec:cpe": {
"#text": "cpe:/o:kddi:hgw_bl1500hm_firmware",
"@product": "HGW BL1500HM firmware",
"@vendor": "KDDI",
"@version": "2.2"
},
"sec:cvss": {
"@score": "8.8",
"@severity": "High",
"@type": "Base",
"@vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2024-003016",
"sec:references": [
{
"#text": "https://jvn.jp/en/vu/JVNVU93546510/index.html",
"@id": "JVNVU#93546510",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2024-21865",
"@id": "CVE-2024-21865",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2024-28041",
"@id": "CVE-2024-28041",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2024-29071",
"@id": "CVE-2024-29071",
"@source": "CVE"
},
{
"#text": "https://cwe.mitre.org/data/definitions/1391.html",
"@id": "CWE-1391",
"@title": "Use of Weak Credentials(CWE-1391)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/77.html",
"@id": "CWE-77",
"@title": "Command Injection(CWE-77)"
}
],
"title": "Multiple vulnerabilities in home gateway HGW BL1500HM"
}
JVNDB-2024-001804
Vulnerability from jvndb - Published: 2024-02-06 06:02 - Updated:2024-03-11 08:32
Severity
Summary
Multiple buffer overflow vulnerabilities in HOME SPOT CUBE2
Details
HOME SPOT CUBE2 provided by KDDI CORPORATION contains multiple vulnerabilities listed below.
* Stack-based buffer overflow (CWE-121) - CVE-2024-21780
* Heap-based buffer overflow (CWE-122) - CVE-2024-23978
Chuya Hayakawa of 00One, Inc. reported these vulnerabilities to JPCERT/CC.
JPCERT/CC coordinated with the developer.
References
| Type | URL | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2024/JVNDB-2024-001804.html",
"dc:date": "2024-03-11T17:32+09:00",
"dcterms:issued": "2024-02-06T15:02+09:00",
"dcterms:modified": "2024-03-11T17:32+09:00",
"description": "HOME SPOT CUBE2 provided by KDDI CORPORATION contains multiple vulnerabilities listed below.\r\n\r\n * Stack-based buffer overflow (CWE-121) - CVE-2024-21780\r\n * Heap-based buffer overflow (CWE-122) - CVE-2024-23978\r\n\r\nChuya Hayakawa of 00One, Inc. reported these vulnerabilities to JPCERT/CC.\r\nJPCERT/CC coordinated with the developer.",
"link": "https://jvndb.jvn.jp/en/contents/2024/JVNDB-2024-001804.html",
"sec:cpe": {
"#text": "cpe:/o:kddi:home_spot_cube_2_firmware",
"@product": "HOME SPOT CUBE2 firmware",
"@vendor": "KDDI",
"@version": "2.2"
},
"sec:cvss": {
"@score": "8.8",
"@severity": "High",
"@type": "Base",
"@vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2024-001804",
"sec:references": [
{
"#text": "https://jvn.jp/en/vu/JVNVU93740658/index.html",
"@id": "JVNVU#93740658",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2024-21780",
"@id": "CVE-2024-21780",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2024-23978",
"@id": "CVE-2024-23978",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2024-21780",
"@id": "CVE-2024-21780",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2024-23978",
"@id": "CVE-2024-23978",
"@source": "NVD"
},
{
"#text": "https://cwe.mitre.org/data/definitions/121.html",
"@id": "CWE-121",
"@title": "Stack-based Buffer Overflow(CWE-121)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/122.html",
"@id": "CWE-122",
"@title": "Heap-based Buffer Overflow(CWE-122)"
}
],
"title": "Multiple buffer overflow vulnerabilities in HOME SPOT CUBE2"
}
JVNDB-2022-000101
Vulnerability from jvndb - Published: 2022-12-21 05:13 - Updated:2022-12-21 05:13
Severity
Summary
+Message App improper handling of Unicode control characters
Details
+Message App displays text unprocessed, even when control characters are contained, and the text is shown based on Unicode control character's specifications.
Therefore, a crafted text may display misleading web links (CWE-451).
Akaki Tsunoda reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
References
| Type | URL | |
|---|---|---|
Impacted products
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-000101.html",
"dc:date": "2022-12-21T14:13+09:00",
"dcterms:issued": "2022-12-21T14:13+09:00",
"dcterms:modified": "2022-12-21T14:13+09:00",
"description": "+Message App displays text unprocessed, even when control characters are contained, and the text is shown based on Unicode control character\u0027s specifications.\r\nTherefore, a crafted text may display misleading web links (CWE-451).\r\n\r\nAkaki Tsunoda reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-000101.html",
"sec:cpe": [
{
"#text": "cpe:/a:kddi:%2b_message",
"@product": "+Message (PlusMessage)",
"@vendor": "KDDI",
"@version": "2.2"
},
{
"#text": "cpe:/a:nttdocomo:%2b_message",
"@product": "+Message (PlusMessage)",
"@vendor": "NTT DOCOMO, INC.",
"@version": "2.2"
},
{
"#text": "cpe:/a:softbank:%2b_message",
"@product": "+Message (PlusMessage)",
"@vendor": "SoftBank",
"@version": "2.2"
}
],
"sec:cvss": [
{
"@score": "4.3",
"@severity": "Medium",
"@type": "Base",
"@vector": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"@version": "2.0"
},
{
"@score": "4.3",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2022-000101",
"sec:references": [
{
"#text": "https://jvn.jp/en/jp/JVN43561812/index.html",
"@id": "JVN#43561812",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2022-43543",
"@id": "CVE-2022-43543",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-43543",
"@id": "CVE-2022-43543",
"@source": "NVD"
},
{
"#text": "https://unicode.org/reports/tr36/",
"@id": "Unicode Technical Report #36",
"@source": "Related document"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-Other",
"@title": "No Mapping(CWE-Other)"
}
],
"title": "+Message App improper handling of Unicode control characters"
}
JVNDB-2022-000049
Vulnerability from jvndb - Published: 2022-06-29 04:42 - Updated:2024-06-17 01:45
Severity
Summary
HOME SPOT CUBE2 vulnerable to OS command injection
Details
HOME SPOT CUBE2 provided by KDDI CORPORATION contains an OS command injection vulnerability (CWE-78) due to improper processing of data received from DHCP server.
Alice Rose reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
References
| Type | URL | |
|---|---|---|
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-000049.html",
"dc:date": "2024-06-17T10:45+09:00",
"dcterms:issued": "2022-06-29T13:42+09:00",
"dcterms:modified": "2024-06-17T10:45+09:00",
"description": "HOME SPOT CUBE2 provided by KDDI CORPORATION contains an OS command injection vulnerability (CWE-78) due to improper processing of data received from DHCP server.\r\n\r\nAlice Rose reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-000049.html",
"sec:cpe": {
"#text": "cpe:/h:kddi:home_spot_cube_2",
"@product": "HOME SPOT CUBE2",
"@vendor": "KDDI",
"@version": "2.2"
},
"sec:cvss": [
{
"@score": "5.8",
"@severity": "Medium",
"@type": "Base",
"@vector": "AV:A/AC:L/Au:N/C:P/I:P/A:P",
"@version": "2.0"
},
{
"@score": "8.8",
"@severity": "High",
"@type": "Base",
"@vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2022-000049",
"sec:references": [
{
"#text": "http://jvn.jp/en/jp/JVN41017328/index.html",
"@id": "JVN#41017328",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2022-33948",
"@id": "CVE-2022-33948",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-33948",
"@id": "CVE-2022-33948",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-78",
"@title": "OS Command Injection(CWE-78)"
}
],
"title": "HOME SPOT CUBE2 vulnerable to OS command injection"
}
JVNDB-2019-000053
Vulnerability from jvndb - Published: 2019-08-23 06:57 - Updated:2019-10-08 08:35
Severity
Summary
Smart TV Box fails to restrict access permissions
Details
Smart TV Box provided by KDDI CORPORATION enables access to Android Debug Bridge via port 5555/TCP of LAN side interface.
When a cable television provider sets up Smart TV Box at an individual residence, direct access from outside to the LAN side interface of Smart TV Box is disabled. However if the original setting is changed later, for example, LAN side interface connection to internet directly is enabled, access to Android Debug Bridge via port 5555/TCP of LAN side interface becomes enabled. As a result, arbitrary operations without users intent becomes possible, and a remote attacker may conduct arbitrary operations on the device.
Yoshiki Mori and Masaki Kubo of Cybersecurity Laboratory, National Institute of Information and Communications Technology reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
References
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2019/JVNDB-2019-000053.html",
"dc:date": "2019-10-08T17:35+09:00",
"dcterms:issued": "2019-08-23T15:57+09:00",
"dcterms:modified": "2019-10-08T17:35+09:00",
"description": "Smart TV Box provided by KDDI CORPORATION enables access to Android Debug Bridge via port 5555/TCP of LAN side interface.\r\nWhen a cable television provider sets up Smart TV Box at an individual residence, direct access from outside to the LAN side interface of Smart TV Box is disabled. However if the original setting is changed later, for example, LAN side interface connection to internet directly is enabled, access to Android Debug Bridge via port 5555/TCP of LAN side interface becomes enabled. As a result, arbitrary operations without users intent becomes possible, and a remote attacker may conduct arbitrary operations on the device.\r\n\r\nYoshiki Mori and Masaki Kubo of Cybersecurity Laboratory, National Institute of Information and Communications Technology reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2019/JVNDB-2019-000053.html",
"sec:cpe": {
"#text": "cpe:/o:kddi:smart_tv_box_firmware",
"@product": "Smart TV Box",
"@vendor": "KDDI",
"@version": "2.2"
},
"sec:cvss": [
{
"@score": "6.8",
"@severity": "Medium",
"@type": "Base",
"@vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"@version": "2.0"
},
{
"@score": "7.3",
"@severity": "High",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2019-000053",
"sec:references": [
{
"#text": "https://jvn.jp/en/jp/JVN17127920/index.html",
"@id": "JVN#17127920",
"@source": "JVN"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6005",
"@id": "CVE-2019-6005",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2019-6005",
"@id": "CVE-2019-6005",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-Other",
"@title": "No Mapping(CWE-Other)"
}
],
"title": "Smart TV Box fails to restrict access permissions"
}
JVNDB-2018-000100
Vulnerability from jvndb - Published: 2018-09-27 07:52 - Updated:2019-08-27 08:22
Severity
Summary
+Message App fails to verify SSL server certificates
Details
+Message App fails to verify SSL server certificates.
ma.la of LINE Corporation reported this vulnerability to the developer, and also to IPA in order to notify users of its solution through JVN.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
References
Impacted products
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2018/JVNDB-2018-000100.html",
"dc:date": "2019-08-27T17:22+09:00",
"dcterms:issued": "2018-09-27T16:52+09:00",
"dcterms:modified": "2019-08-27T17:22+09:00",
"description": "+Message App fails to verify SSL server certificates.\r\n\r\nma.la of LINE Corporation reported this vulnerability to the developer, and also to IPA in order to notify users of its solution through JVN.\r\n JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2018/JVNDB-2018-000100.html",
"sec:cpe": [
{
"#text": "cpe:/a:kddi:%2b_message",
"@product": "+Message (PlusMessage)",
"@vendor": "KDDI",
"@version": "2.2"
},
{
"#text": "cpe:/a:nttdocomo:%2b_message",
"@product": "+Message (PlusMessage)",
"@vendor": "NTT DOCOMO, INC.",
"@version": "2.2"
},
{
"#text": "cpe:/a:softbank:%2b_message",
"@product": "+Message (PlusMessage)",
"@vendor": "SoftBank",
"@version": "2.2"
}
],
"sec:cvss": [
{
"@score": "4.0",
"@severity": "Medium",
"@type": "Base",
"@vector": "AV:N/AC:H/Au:N/C:P/I:P/A:N",
"@version": "2.0"
},
{
"@score": "4.8",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2018-000100",
"sec:references": [
{
"#text": "https://jvn.jp/en/jp/JVN37288228/",
"@id": "JVN#37288228",
"@source": "JVN"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0691",
"@id": "CVE-2018-0691",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2018-0691",
"@id": "CVE-2018-0691",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-Other",
"@title": "No Mapping(CWE-Other)"
}
],
"title": "+Message App fails to verify SSL server certificates"
}
JVNDB-2018-000009
Vulnerability from jvndb - Published: 2018-02-06 06:05 - Updated:2018-04-11 03:13
Severity
Summary
The installer of Anshin net security for Windows may insecurely load Dynamic Link Libraries
Details
Anshin net security for Windows provided by KDDI CORPORATION is an Internet Security suite. The installer of Anshin net security for Windows contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427).
Eili Masami of Tachibana Lab. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
References
| Type | URL | |
|---|---|---|
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2018/JVNDB-2018-000009.html",
"dc:date": "2018-04-11T12:13+09:00",
"dcterms:issued": "2018-02-06T15:05+09:00",
"dcterms:modified": "2018-04-11T12:13+09:00",
"description": "Anshin net security for Windows provided by KDDI CORPORATION is an Internet Security suite. The installer of Anshin net security for Windows contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427).\r\n\r\nEili Masami of Tachibana Lab. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2018/JVNDB-2018-000009.html",
"sec:cpe": {
"#text": "cpe:/a:kddi:anshin_net_security",
"@product": "Anshin net security",
"@vendor": "KDDI",
"@version": "2.2"
},
"sec:cvss": [
{
"@score": "6.8",
"@severity": "Medium",
"@type": "Base",
"@vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"@version": "2.0"
},
{
"@score": "7.8",
"@severity": "High",
"@type": "Base",
"@vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2018-000009",
"sec:references": [
{
"#text": "http://jvn.jp/en/jp/JVN70615027/index.html",
"@id": "JVN#70615027",
"@source": "JVN"
},
{
"#text": "https://jvn.jp/en/ta/JVNTA91240916/index.html",
"@id": "JVNTA#91240916",
"@source": "JVN"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0517",
"@id": "CVE-2018-0517",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2018-0517",
"@id": "CVE-2018-0517",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-Other",
"@title": "No Mapping(CWE-Other)"
}
],
"title": "The installer of Anshin net security for Windows may insecurely load Dynamic Link Libraries"
}
JVNDB-2017-000191
Vulnerability from jvndb - Published: 2017-08-08 06:35 - Updated:2018-02-14 03:14
Severity
Summary
Installer of Qua station connection tool for Windows may insecurely load Dynamic Link Libraries
Details
Qua station provided KDDI CORPORATION is a 4G LTE photostrage. Qua station connection tool is used to view data saved on Qua station from a PC and/or save data on a PC. Installer of Qua station connection tool for Windows contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427).
Eili Masami of Tachibana Lab. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
References
| Type | URL | |
|---|---|---|
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000191.html",
"dc:date": "2018-02-14T12:14+09:00",
"dcterms:issued": "2017-08-08T15:35+09:00",
"dcterms:modified": "2018-02-14T12:14+09:00",
"description": "Qua station provided KDDI CORPORATION is a 4G LTE photostrage. Qua station connection tool is used to view data saved on Qua station from a PC and/or save data on a PC. Installer of Qua station connection tool for Windows contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427).\r\n\r\nEili Masami of Tachibana Lab. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000191.html",
"sec:cpe": {
"#text": "cpe:/h:kddi:qua_station",
"@product": "Qua station connection tool",
"@vendor": "KDDI",
"@version": "2.2"
},
"sec:cvss": [
{
"@score": "6.8",
"@severity": "Medium",
"@type": "Base",
"@vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"@version": "2.0"
},
{
"@score": "7.8",
"@severity": "High",
"@type": "Base",
"@vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2017-000191",
"sec:references": [
{
"#text": "http://jvn.jp/en/jp/JVN81659403/index.html",
"@id": "JVN#81659403",
"@source": "JVN"
},
{
"#text": "https://jvn.jp/en/ta/JVNTA91240916/index.html",
"@id": "JVNTA#91240916",
"@source": "JVN"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2289",
"@id": "CVE-2017-2289",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2017-2289",
"@id": "CVE-2017-2289",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-Other",
"@title": "No Mapping(CWE-Other)"
}
],
"title": "Installer of Qua station connection tool for Windows may insecurely load Dynamic Link Libraries"
}
JVNDB-2017-000138
Vulnerability from jvndb - Published: 2017-06-21 04:45 - Updated:2018-02-14 02:59
Severity
Summary
HOME SPOT CUBE2 vulnerable to improper authentication in WebUI
Details
HOME SPOT CUBE2 provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE2 contains improper authentication in WebUI.
Taizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
References
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000138.html",
"dc:date": "2018-02-14T11:59+09:00",
"dcterms:issued": "2017-06-21T13:45+09:00",
"dcterms:modified": "2018-02-14T11:59+09:00",
"description": "HOME SPOT CUBE2 provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE2 contains improper authentication in WebUI.\r\n\r\nTaizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000138.html",
"sec:cpe": {
"#text": "cpe:/o:kddi:home_spot_cube_2_firmware",
"@product": "HOME SPOT CUBE2 firmware",
"@vendor": "KDDI",
"@version": "2.2"
},
"sec:cvss": [
{
"@score": "3.3",
"@severity": "Low",
"@type": "Base",
"@vector": "AV:A/AC:L/Au:N/C:N/I:P/A:N",
"@version": "2.0"
},
{
"@score": "6.5",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2017-000138",
"sec:references": [
{
"#text": "http://jvn.jp/en/jp/JVN24348065/index.html",
"@id": "JVN#24348065",
"@source": "JVN"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2186",
"@id": "CVE-2017-2186",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2017-2186",
"@id": "CVE-2017-2186",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-264",
"@title": "Permissions(CWE-264)"
}
],
"title": "HOME SPOT CUBE2 vulnerable to improper authentication in WebUI"
}
JVNDB-2017-000137
Vulnerability from jvndb - Published: 2017-06-21 04:45 - Updated:2018-02-14 02:59
Severity
Summary
HOME SPOT CUBE2 vulnerable to OS command injection in WebUI
Details
HOME SPOT CUBE2 provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE2 contains OS command injection in WebUI.
Taizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
References
| Type | URL | |
|---|---|---|
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000137.html",
"dc:date": "2018-02-14T11:59+09:00",
"dcterms:issued": "2017-06-21T13:45+09:00",
"dcterms:modified": "2018-02-14T11:59+09:00",
"description": "HOME SPOT CUBE2 provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE2 contains OS command injection in WebUI.\r\n\r\nTaizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000137.html",
"sec:cpe": {
"#text": "cpe:/o:kddi:home_spot_cube_2_firmware",
"@product": "HOME SPOT CUBE2 firmware",
"@vendor": "KDDI",
"@version": "2.2"
},
"sec:cvss": [
{
"@score": "5.2",
"@severity": "Medium",
"@type": "Base",
"@vector": "AV:A/AC:L/Au:S/C:P/I:P/A:P",
"@version": "2.0"
},
{
"@score": "6.8",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2017-000137",
"sec:references": [
{
"#text": "http://jvn.jp/en/jp/JVN24348065/index.html",
"@id": "JVN#24348065",
"@source": "JVN"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2185",
"@id": "CVE-2017-2185",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2017-2185",
"@id": "CVE-2017-2185",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-78",
"@title": "OS Command Injection(CWE-78)"
}
],
"title": "HOME SPOT CUBE2 vulnerable to OS command injection in WebUI"
}
JVNDB-2017-000136
Vulnerability from jvndb - Published: 2017-06-21 04:44 - Updated:2018-02-14 02:59
Severity
Summary
HOME SPOT CUBE2 vulnerable to buffer overflow in WebUI
Details
HOME SPOT CUBE2 provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE2 contains buffer overflow in WebUI.
Taizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
References
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000136.html",
"dc:date": "2018-02-14T11:59+09:00",
"dcterms:issued": "2017-06-21T13:44+09:00",
"dcterms:modified": "2018-02-14T11:59+09:00",
"description": "HOME SPOT CUBE2 provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE2 contains buffer overflow in WebUI.\r\n\r\nTaizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000136.html",
"sec:cpe": {
"#text": "cpe:/o:kddi:home_spot_cube_2_firmware",
"@product": "HOME SPOT CUBE2 firmware",
"@vendor": "KDDI",
"@version": "2.2"
},
"sec:cvss": [
{
"@score": "5.8",
"@severity": "Medium",
"@type": "Base",
"@vector": "AV:A/AC:L/Au:N/C:P/I:P/A:P",
"@version": "2.0"
},
{
"@score": "8.8",
"@severity": "High",
"@type": "Base",
"@vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2017-000136",
"sec:references": [
{
"#text": "http://jvn.jp/en/jp/JVN24348065/index.html",
"@id": "JVN#24348065",
"@source": "JVN"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2184",
"@id": "CVE-2017-2184",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2017-2184",
"@id": "CVE-2017-2184",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-119",
"@title": "Buffer Errors(CWE-119)"
}
],
"title": "HOME SPOT CUBE2 vulnerable to buffer overflow in WebUI"
}
JVNDB-2017-000135
Vulnerability from jvndb - Published: 2017-06-21 04:44 - Updated:2018-02-14 02:54
Severity
Summary
HOME SPOT CUBE2 vulnerable to OS command injection in clock settings
Details
HOME SPOT CUBE2 provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE2 contains OS command injection in clock settings.
Taizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
References
| Type | URL | |
|---|---|---|
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000135.html",
"dc:date": "2018-02-14T11:54+09:00",
"dcterms:issued": "2017-06-21T13:44+09:00",
"dcterms:modified": "2018-02-14T11:54+09:00",
"description": "HOME SPOT CUBE2 provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE2 contains OS command injection in clock settings.\r\n\r\nTaizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000135.html",
"sec:cpe": {
"#text": "cpe:/o:kddi:home_spot_cube_2_firmware",
"@product": "HOME SPOT CUBE2 firmware",
"@vendor": "KDDI",
"@version": "2.2"
},
"sec:cvss": [
{
"@score": "5.2",
"@severity": "Medium",
"@type": "Base",
"@vector": "AV:A/AC:L/Au:S/C:P/I:P/A:P",
"@version": "2.0"
},
{
"@score": "6.8",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2017-000135",
"sec:references": [
{
"#text": "http://jvn.jp/en/jp/JVN24348065/index.html",
"@id": "JVN#24348065",
"@source": "JVN"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2183",
"@id": "CVE-2017-2183",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2017-2183",
"@id": "CVE-2017-2183",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-78",
"@title": "OS Command Injection(CWE-78)"
}
],
"title": "HOME SPOT CUBE2 vulnerable to OS command injection in clock settings"
}
JVNDB-2016-000008
Vulnerability from jvndb - Published: 2016-01-27 05:40 - Updated:2016-02-16 08:26
Severity
Summary
HOME SPOT CUBE vulnerable to open redirect
Details
HOME SPOT CUBE provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE contains an open redirect vulnerability.
Masaki Yoshikawa of LAC Co., Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
References
| Type | URL | |
|---|---|---|
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000008.html",
"dc:date": "2016-02-16T17:26+09:00",
"dcterms:issued": "2016-01-27T14:40+09:00",
"dcterms:modified": "2016-02-16T17:26+09:00",
"description": "HOME SPOT CUBE provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE contains an open redirect vulnerability.\r\n\r\nMasaki Yoshikawa of LAC Co., Ltd. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000008.html",
"sec:cpe": {
"#text": "cpe:/h:kddi:home_spot_cube",
"@product": "HOME SPOT CUBE",
"@vendor": "KDDI",
"@version": "2.2"
},
"sec:cvss": [
{
"@score": "2.6",
"@severity": "Low",
"@type": "Base",
"@vector": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
"@version": "2.0"
},
{
"@score": "4.7",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2016-000008",
"sec:references": [
{
"#text": "https://jvn.jp/en/jp/JVN54686544/index.html",
"@id": "JVN#54686544",
"@source": "JVN"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1137",
"@id": "CVE-2016-1137",
"@source": "CVE"
},
{
"#text": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-1137",
"@id": "CVE-2016-1137",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-20",
"@title": "Improper Input Validation(CWE-20)"
}
],
"title": "HOME SPOT CUBE vulnerable to open redirect"
}
JVNDB-2016-000009
Vulnerability from jvndb - Published: 2016-01-27 05:40 - Updated:2016-02-16 08:26
Severity
Summary
HOME SPOT CUBE vulnerable to HTTP header injection
Details
HOME SPOT CUBE provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE contains a HTTP header injection vulnerability.
Masaki Yoshikawa of LAC Co., Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
References
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000009.html",
"dc:date": "2016-02-16T17:26+09:00",
"dcterms:issued": "2016-01-27T14:40+09:00",
"dcterms:modified": "2016-02-16T17:26+09:00",
"description": "HOME SPOT CUBE provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE contains a HTTP header injection vulnerability.\r\n\r\nMasaki Yoshikawa of LAC Co., Ltd. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000009.html",
"sec:cpe": {
"#text": "cpe:/h:kddi:home_spot_cube",
"@product": "HOME SPOT CUBE",
"@vendor": "KDDI",
"@version": "2.2"
},
"sec:cvss": [
{
"@score": "2.6",
"@severity": "Low",
"@type": "Base",
"@vector": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
"@version": "2.0"
},
{
"@score": "4.7",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2016-000009",
"sec:references": [
{
"#text": "https://jvn.jp/en/jp/JVN54686544/index.html",
"@id": "JVN#54686544",
"@source": "JVN"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1138",
"@id": "CVE-2016-1138",
"@source": "CVE"
},
{
"#text": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-1138",
"@id": "CVE-2016-1138",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-Other",
"@title": "No Mapping(CWE-Other)"
}
],
"title": "HOME SPOT CUBE vulnerable to HTTP header injection"
}
JVNDB-2016-000011
Vulnerability from jvndb - Published: 2016-01-27 05:40 - Updated:2016-02-16 08:26
Severity
Summary
HOME SPOT CUBE vulnerable to clickjacking
Details
HOME SPOT CUBE provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE contains a clickjacking vulnerabilitiy.
Masaki Yoshikawa of LAC Co., Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
References
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000011.html",
"dc:date": "2016-02-16T17:26+09:00",
"dcterms:issued": "2016-01-27T14:40+09:00",
"dcterms:modified": "2016-02-16T17:26+09:00",
"description": "HOME SPOT CUBE provided by KDDI CORPORATION is a wireless LAN router. HOME SPOT CUBE contains a clickjacking vulnerabilitiy.\r\n\r\nMasaki Yoshikawa of LAC Co., Ltd. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000011.html",
"sec:cpe": {
"#text": "cpe:/h:kddi:home_spot_cube",
"@product": "HOME SPOT CUBE",
"@vendor": "KDDI",
"@version": "2.2"
},
"sec:cvss": [
{
"@score": "2.6",
"@severity": "Low",
"@type": "Base",
"@vector": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
"@version": "2.0"
},
{
"@score": "4.3",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2016-000011",
"sec:references": [
{
"#text": "http://jvn.jp/en/jp/JVN54686544/index.html",
"@id": "JVN#54686544",
"@source": "JVN"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1140",
"@id": "CVE-2016-1140",
"@source": "CVE"
},
{
"#text": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-1140",
"@id": "CVE-2016-1140",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-Other",
"@title": "No Mapping(CWE-Other)"
}
],
"title": "HOME SPOT CUBE vulnerable to clickjacking"
}
CVE-2024-29071 (GCVE-0-2024-29071)
Vulnerability from nvd – Published: 2024-03-25 03:42 – Updated: 2025-03-28 07:38
VLAI
EPSS
VEX
Summary
HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change the system settings.
Severity
8.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-11-04 13:53 UTC
Assigner
References
3 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| KDDI CORPORATION | HGW BL1500HM |
Affected:
Ver 002.001.013 and earlier
|
|
| kddi | hgw_bli500hm_firmware |
Affected:
0 , ≤ 002.001.013
(custom)
cpe:2.3:o:kddi:hgw_bli500hm_firmware:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:o:kddi:hgw_bli500hm_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "hgw_bli500hm_firmware",
"vendor": "kddi",
"versions": [
{
"lessThanOrEqual": "002.001.013",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2024-29071",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-11-04T13:53:58.969525Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-522",
"description": "CWE-522 Insufficiently Protected Credentials",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-11-04T13:55:29.279Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-02T01:03:51.863Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://www.au.com/support/service/internet/guide/modem/bl1500hm/firmware/"
},
{
"tags": [
"x_transferred"
],
"url": "https://jvn.jp/en/vu/JVNVU93546510/"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "HGW BL1500HM",
"vendor": "KDDI CORPORATION",
"versions": [
{
"status": "affected",
"version": "Ver 002.001.013 and earlier"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change the system settings."
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1391",
"description": "Use of weak credentials",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-03-28T07:38:42.105Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://kddi-tech.com/contents/appendix_L2_06.html#20304f4c-af1b-49fd-c3b5-8d1f55fd8b4f"
},
{
"url": "https://jvn.jp/en/vu/JVNVU93546510/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2024-29071",
"datePublished": "2024-03-25T03:42:31.070Z",
"dateReserved": "2024-03-18T01:23:31.527Z",
"dateUpdated": "2025-03-28T07:38:42.105Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2024-28041 (GCVE-0-2024-28041)
Vulnerability from nvd – Published: 2024-03-25 03:42 – Updated: 2025-03-28 07:39
VLAI
EPSS
VEX
Summary
HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary command.
Severity
8.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-07-17 15:30 UTC
CWE
- Arbitrary command execution
- CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
Assigner
References
3 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| KDDI CORPORATION | HGW BL1500HM |
Affected:
Ver 002.001.013 and earlier
|
|
| kddi | hgw_bli500hm_firmware |
Affected:
0 , ≤ 002.001.013
(custom)
cpe:2.3:o:kddi:hgw_bli500hm_firmware:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:o:kddi:hgw_bli500hm_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "hgw_bli500hm_firmware",
"vendor": "kddi",
"versions": [
{
"lessThanOrEqual": "002.001.013",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2024-28041",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-07-17T15:30:23.593154Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-77",
"description": "CWE-77 Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-07-17T15:32:08.389Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-02T00:48:47.724Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://www.au.com/support/service/internet/guide/modem/bl1500hm/firmware/"
},
{
"tags": [
"x_transferred"
],
"url": "https://jvn.jp/en/vu/JVNVU93546510/"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "HGW BL1500HM",
"vendor": "KDDI CORPORATION",
"versions": [
{
"status": "affected",
"version": "Ver 002.001.013 and earlier"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary command."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Arbitrary command execution",
"lang": "en-US",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-03-28T07:39:02.488Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://kddi-tech.com/contents/appendix_L2_06.html#20304f4c-af1b-49fd-c3b5-8d1f55fd8b4f"
},
{
"url": "https://jvn.jp/en/vu/JVNVU93546510/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2024-28041",
"datePublished": "2024-03-25T03:42:17.754Z",
"dateReserved": "2024-03-18T01:23:33.325Z",
"dateUpdated": "2025-03-28T07:39:02.488Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2022-43543 (GCVE-0-2022-43543)
Vulnerability from nvd – Published: 2022-12-21 00:00 – Updated: 2025-04-16 17:36
VLAI
EPSS
VEX
Summary
KDDI +Message App, NTT DOCOMO +Message App, and SoftBank +Message App contain a vulnerability caused by improper handling of Unicode control characters. +Message App displays text unprocessed, even when control characters are contained, and the text is shown based on Unicode control character's specifications. Therefore, a crafted text may display misleading web links. As a result, a spoofed URL may be displayed and phishing attacks may be conducted. Affected products and versions are as follows: KDDI +Message App for Android prior to version 3.9.2 and +Message App for iOS prior to version 3.9.4, NTT DOCOMO +Message App for Android prior to version 54.49.0500 and +Message App for iOS prior to version 3.9.4, and SoftBank +Message App for Android prior to version 12.9.5 and +Message App for iOS prior to version 3.9.4
Severity
5.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-04-16 17:36 UTC
CWE
- User Interface (UI) Misrepresentation of Critical Information
- CWE-116 - Improper Encoding or Escaping of Output
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| KDDI CORPORATION, NTT DOCOMO, INC., and SoftBank Corp. | KDDI +Message App for Android and for iOS, NTT DOCOMO +Message App for Android and for iOS, and SoftBank +Message App for Android and for iOS |
Affected:
KDDI +Message App for Android prior to version 3.9.2 and +Message App for iOS prior to version 3.9.4, NTT DOCOMO +Message App for Android prior to version 54.49.0500 and +Message App for iOS prior to version 3.9.4, and SoftBank +Message App for Android prior to version 12.9.5 and +Message App for iOS prior to version 3.9.4
|
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T13:32:59.662Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://www.au.com/mobile/service/plus-message/information/"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.docomo.ne.jp/service/plus_message/"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.softbank.jp/mobile/service/plus-message/"
},
{
"tags": [
"x_transferred"
],
"url": "https://jvn.jp/en/jp/JVN43561812/index.html"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2022-43543",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-04-16T17:36:38.691998Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-116",
"description": "CWE-116 Improper Encoding or Escaping of Output",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-04-16T17:36:43.679Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "KDDI +Message App for Android and for iOS, NTT DOCOMO +Message App for Android and for iOS, and SoftBank +Message App for Android and for iOS",
"vendor": "KDDI CORPORATION, NTT DOCOMO, INC., and SoftBank Corp.",
"versions": [
{
"status": "affected",
"version": "KDDI +Message App for Android prior to version 3.9.2 and +Message App for iOS prior to version 3.9.4, NTT DOCOMO +Message App for Android prior to version 54.49.0500 and +Message App for iOS prior to version 3.9.4, and SoftBank +Message App for Android prior to version 12.9.5 and +Message App for iOS prior to version 3.9.4"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "KDDI +Message App, NTT DOCOMO +Message App, and SoftBank +Message App contain a vulnerability caused by improper handling of Unicode control characters. +Message App displays text unprocessed, even when control characters are contained, and the text is shown based on Unicode control character\u0027s specifications. Therefore, a crafted text may display misleading web links. As a result, a spoofed URL may be displayed and phishing attacks may be conducted. Affected products and versions are as follows: KDDI +Message App for Android prior to version 3.9.2 and +Message App for iOS prior to version 3.9.4, NTT DOCOMO +Message App for Android prior to version 54.49.0500 and +Message App for iOS prior to version 3.9.4, and SoftBank +Message App for Android prior to version 12.9.5 and +Message App for iOS prior to version 3.9.4"
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "User Interface (UI) Misrepresentation of Critical Information",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2022-12-21T00:00:00.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://www.au.com/mobile/service/plus-message/information/"
},
{
"url": "https://www.docomo.ne.jp/service/plus_message/"
},
{
"url": "https://www.softbank.jp/mobile/service/plus-message/"
},
{
"url": "https://jvn.jp/en/jp/JVN43561812/index.html"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2022-43543",
"datePublished": "2022-12-21T00:00:00.000Z",
"dateReserved": "2022-12-14T00:00:00.000Z",
"dateUpdated": "2025-04-16T17:36:43.679Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2018-0691 (GCVE-0-2018-0691)
Vulnerability from nvd – Published: 2018-11-15 15:00 – Updated: 2024-08-05 03:35
VLAI
EPSS
VEX
Summary
Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23) do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Severity
No CVSS data available.
CWE
- Fails to verify SSL certificates
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://www.au.com/information/notice_mobile/serv… | x_refsource_MISC |
| https://www.softbank.jp/mobile/info/personal/news… | x_refsource_MISC |
| http://jvn.jp/en/jp/JVN37288228/index.html | third-party-advisoryx_refsource_JVN |
| https://www.nttdocomo.co.jp/info/notice/page/1809… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Softbank, NTT docomo, KDDI | Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23) |
Affected:
Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23
|
Date Public
2018-11-15 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T03:35:49.057Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://www.au.com/information/notice_mobile/service/2018-002/"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://www.softbank.jp/mobile/info/personal/news/service/20180927a/"
},
{
"name": "JVN#37288228",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN37288228/index.html"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://www.nttdocomo.co.jp/info/notice/page/180927_00.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23)",
"vendor": "Softbank, NTT docomo, KDDI",
"versions": [
{
"status": "affected",
"version": "Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23"
}
]
}
],
"datePublic": "2018-11-15T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23) do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Fails to verify SSL certificates",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2018-11-15T14:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://www.au.com/information/notice_mobile/service/2018-002/"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://www.softbank.jp/mobile/info/personal/news/service/20180927a/"
},
{
"name": "JVN#37288228",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "http://jvn.jp/en/jp/JVN37288228/index.html"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://www.nttdocomo.co.jp/info/notice/page/180927_00.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2018-0691",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23)",
"version": {
"version_data": [
{
"version_value": "Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23"
}
]
}
}
]
},
"vendor_name": "Softbank, NTT docomo, KDDI"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23) do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Fails to verify SSL certificates"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://www.au.com/information/notice_mobile/service/2018-002/",
"refsource": "MISC",
"url": "https://www.au.com/information/notice_mobile/service/2018-002/"
},
{
"name": "https://www.softbank.jp/mobile/info/personal/news/service/20180927a/",
"refsource": "MISC",
"url": "https://www.softbank.jp/mobile/info/personal/news/service/20180927a/"
},
{
"name": "JVN#37288228",
"refsource": "JVN",
"url": "http://jvn.jp/en/jp/JVN37288228/index.html"
},
{
"name": "https://www.nttdocomo.co.jp/info/notice/page/180927_00.html",
"refsource": "MISC",
"url": "https://www.nttdocomo.co.jp/info/notice/page/180927_00.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2018-0691",
"datePublished": "2018-11-15T15:00:00.000Z",
"dateReserved": "2017-11-27T00:00:00.000Z",
"dateUpdated": "2024-08-05T03:35:49.057Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2018-0517 (GCVE-0-2018-0517)
Vulnerability from nvd – Published: 2018-02-08 14:00 – Updated: 2024-08-05 03:28
VLAI
EPSS
VEX
Summary
Untrusted search path vulnerability in Anshin net security for Windows Version 16.0.1.44 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Severity
No CVSS data available.
CWE
- Untrusted search path vulnerability
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://jvn.jp/en/jp/JVN70615027/index.html | third-party-advisoryx_refsource_JVN |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| KDDI CORPORATION | Anshin net security for Windows |
Affected:
Version 16.0.1.44 and earlier
|
Date Public
2018-02-06 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T03:28:11.086Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "JVN#70615027",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "https://jvn.jp/en/jp/JVN70615027/index.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "Anshin net security for Windows",
"vendor": "KDDI CORPORATION",
"versions": [
{
"status": "affected",
"version": "Version 16.0.1.44 and earlier"
}
]
}
],
"datePublic": "2018-02-06T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Untrusted search path vulnerability in Anshin net security for Windows Version 16.0.1.44 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Untrusted search path vulnerability",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2018-02-08T13:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "JVN#70615027",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "https://jvn.jp/en/jp/JVN70615027/index.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2018-0517",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Anshin net security for Windows",
"version": {
"version_data": [
{
"version_value": "Version 16.0.1.44 and earlier"
}
]
}
}
]
},
"vendor_name": "KDDI CORPORATION"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability in Anshin net security for Windows Version 16.0.1.44 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "JVN#70615027",
"refsource": "JVN",
"url": "https://jvn.jp/en/jp/JVN70615027/index.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2018-0517",
"datePublished": "2018-02-08T14:00:00.000Z",
"dateReserved": "2017-11-27T00:00:00.000Z",
"dateUpdated": "2024-08-05T03:28:11.086Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2024-29071 (GCVE-0-2024-29071)
Vulnerability from cvelistv5 – Published: 2024-03-25 03:42 – Updated: 2025-03-28 07:38
VLAI
EPSS
VEX
Summary
HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change the system settings.
Severity
8.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-11-04 13:53 UTC
Assigner
References
3 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| KDDI CORPORATION | HGW BL1500HM |
Affected:
Ver 002.001.013 and earlier
|
|
| kddi | hgw_bli500hm_firmware |
Affected:
0 , ≤ 002.001.013
(custom)
cpe:2.3:o:kddi:hgw_bli500hm_firmware:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:o:kddi:hgw_bli500hm_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "hgw_bli500hm_firmware",
"vendor": "kddi",
"versions": [
{
"lessThanOrEqual": "002.001.013",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2024-29071",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-11-04T13:53:58.969525Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-522",
"description": "CWE-522 Insufficiently Protected Credentials",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-11-04T13:55:29.279Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-02T01:03:51.863Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://www.au.com/support/service/internet/guide/modem/bl1500hm/firmware/"
},
{
"tags": [
"x_transferred"
],
"url": "https://jvn.jp/en/vu/JVNVU93546510/"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "HGW BL1500HM",
"vendor": "KDDI CORPORATION",
"versions": [
{
"status": "affected",
"version": "Ver 002.001.013 and earlier"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change the system settings."
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1391",
"description": "Use of weak credentials",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-03-28T07:38:42.105Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://kddi-tech.com/contents/appendix_L2_06.html#20304f4c-af1b-49fd-c3b5-8d1f55fd8b4f"
},
{
"url": "https://jvn.jp/en/vu/JVNVU93546510/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2024-29071",
"datePublished": "2024-03-25T03:42:31.070Z",
"dateReserved": "2024-03-18T01:23:31.527Z",
"dateUpdated": "2025-03-28T07:38:42.105Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2024-28041 (GCVE-0-2024-28041)
Vulnerability from cvelistv5 – Published: 2024-03-25 03:42 – Updated: 2025-03-28 07:39
VLAI
EPSS
VEX
Summary
HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary command.
Severity
8.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-07-17 15:30 UTC
CWE
- Arbitrary command execution
- CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
Assigner
References
3 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| KDDI CORPORATION | HGW BL1500HM |
Affected:
Ver 002.001.013 and earlier
|
|
| kddi | hgw_bli500hm_firmware |
Affected:
0 , ≤ 002.001.013
(custom)
cpe:2.3:o:kddi:hgw_bli500hm_firmware:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:o:kddi:hgw_bli500hm_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "hgw_bli500hm_firmware",
"vendor": "kddi",
"versions": [
{
"lessThanOrEqual": "002.001.013",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2024-28041",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-07-17T15:30:23.593154Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-77",
"description": "CWE-77 Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-07-17T15:32:08.389Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-02T00:48:47.724Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://www.au.com/support/service/internet/guide/modem/bl1500hm/firmware/"
},
{
"tags": [
"x_transferred"
],
"url": "https://jvn.jp/en/vu/JVNVU93546510/"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "HGW BL1500HM",
"vendor": "KDDI CORPORATION",
"versions": [
{
"status": "affected",
"version": "Ver 002.001.013 and earlier"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary command."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Arbitrary command execution",
"lang": "en-US",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-03-28T07:39:02.488Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://kddi-tech.com/contents/appendix_L2_06.html#20304f4c-af1b-49fd-c3b5-8d1f55fd8b4f"
},
{
"url": "https://jvn.jp/en/vu/JVNVU93546510/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2024-28041",
"datePublished": "2024-03-25T03:42:17.754Z",
"dateReserved": "2024-03-18T01:23:33.325Z",
"dateUpdated": "2025-03-28T07:39:02.488Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2022-43543 (GCVE-0-2022-43543)
Vulnerability from cvelistv5 – Published: 2022-12-21 00:00 – Updated: 2025-04-16 17:36
VLAI
EPSS
VEX
Summary
KDDI +Message App, NTT DOCOMO +Message App, and SoftBank +Message App contain a vulnerability caused by improper handling of Unicode control characters. +Message App displays text unprocessed, even when control characters are contained, and the text is shown based on Unicode control character's specifications. Therefore, a crafted text may display misleading web links. As a result, a spoofed URL may be displayed and phishing attacks may be conducted. Affected products and versions are as follows: KDDI +Message App for Android prior to version 3.9.2 and +Message App for iOS prior to version 3.9.4, NTT DOCOMO +Message App for Android prior to version 54.49.0500 and +Message App for iOS prior to version 3.9.4, and SoftBank +Message App for Android prior to version 12.9.5 and +Message App for iOS prior to version 3.9.4
Severity
5.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-04-16 17:36 UTC
CWE
- User Interface (UI) Misrepresentation of Critical Information
- CWE-116 - Improper Encoding or Escaping of Output
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| KDDI CORPORATION, NTT DOCOMO, INC., and SoftBank Corp. | KDDI +Message App for Android and for iOS, NTT DOCOMO +Message App for Android and for iOS, and SoftBank +Message App for Android and for iOS |
Affected:
KDDI +Message App for Android prior to version 3.9.2 and +Message App for iOS prior to version 3.9.4, NTT DOCOMO +Message App for Android prior to version 54.49.0500 and +Message App for iOS prior to version 3.9.4, and SoftBank +Message App for Android prior to version 12.9.5 and +Message App for iOS prior to version 3.9.4
|
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T13:32:59.662Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://www.au.com/mobile/service/plus-message/information/"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.docomo.ne.jp/service/plus_message/"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.softbank.jp/mobile/service/plus-message/"
},
{
"tags": [
"x_transferred"
],
"url": "https://jvn.jp/en/jp/JVN43561812/index.html"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2022-43543",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-04-16T17:36:38.691998Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-116",
"description": "CWE-116 Improper Encoding or Escaping of Output",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-04-16T17:36:43.679Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "KDDI +Message App for Android and for iOS, NTT DOCOMO +Message App for Android and for iOS, and SoftBank +Message App for Android and for iOS",
"vendor": "KDDI CORPORATION, NTT DOCOMO, INC., and SoftBank Corp.",
"versions": [
{
"status": "affected",
"version": "KDDI +Message App for Android prior to version 3.9.2 and +Message App for iOS prior to version 3.9.4, NTT DOCOMO +Message App for Android prior to version 54.49.0500 and +Message App for iOS prior to version 3.9.4, and SoftBank +Message App for Android prior to version 12.9.5 and +Message App for iOS prior to version 3.9.4"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "KDDI +Message App, NTT DOCOMO +Message App, and SoftBank +Message App contain a vulnerability caused by improper handling of Unicode control characters. +Message App displays text unprocessed, even when control characters are contained, and the text is shown based on Unicode control character\u0027s specifications. Therefore, a crafted text may display misleading web links. As a result, a spoofed URL may be displayed and phishing attacks may be conducted. Affected products and versions are as follows: KDDI +Message App for Android prior to version 3.9.2 and +Message App for iOS prior to version 3.9.4, NTT DOCOMO +Message App for Android prior to version 54.49.0500 and +Message App for iOS prior to version 3.9.4, and SoftBank +Message App for Android prior to version 12.9.5 and +Message App for iOS prior to version 3.9.4"
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "User Interface (UI) Misrepresentation of Critical Information",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2022-12-21T00:00:00.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://www.au.com/mobile/service/plus-message/information/"
},
{
"url": "https://www.docomo.ne.jp/service/plus_message/"
},
{
"url": "https://www.softbank.jp/mobile/service/plus-message/"
},
{
"url": "https://jvn.jp/en/jp/JVN43561812/index.html"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2022-43543",
"datePublished": "2022-12-21T00:00:00.000Z",
"dateReserved": "2022-12-14T00:00:00.000Z",
"dateUpdated": "2025-04-16T17:36:43.679Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2018-0691 (GCVE-0-2018-0691)
Vulnerability from cvelistv5 – Published: 2018-11-15 15:00 – Updated: 2024-08-05 03:35
VLAI
EPSS
VEX
Summary
Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23) do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Severity
No CVSS data available.
CWE
- Fails to verify SSL certificates
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://www.au.com/information/notice_mobile/serv… | x_refsource_MISC |
| https://www.softbank.jp/mobile/info/personal/news… | x_refsource_MISC |
| http://jvn.jp/en/jp/JVN37288228/index.html | third-party-advisoryx_refsource_JVN |
| https://www.nttdocomo.co.jp/info/notice/page/1809… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Softbank, NTT docomo, KDDI | Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23) |
Affected:
Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23
|
Date Public
2018-11-15 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T03:35:49.057Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://www.au.com/information/notice_mobile/service/2018-002/"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://www.softbank.jp/mobile/info/personal/news/service/20180927a/"
},
{
"name": "JVN#37288228",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN37288228/index.html"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://www.nttdocomo.co.jp/info/notice/page/180927_00.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23)",
"vendor": "Softbank, NTT docomo, KDDI",
"versions": [
{
"status": "affected",
"version": "Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23"
}
]
}
],
"datePublic": "2018-11-15T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23) do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Fails to verify SSL certificates",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2018-11-15T14:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://www.au.com/information/notice_mobile/service/2018-002/"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://www.softbank.jp/mobile/info/personal/news/service/20180927a/"
},
{
"name": "JVN#37288228",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "http://jvn.jp/en/jp/JVN37288228/index.html"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://www.nttdocomo.co.jp/info/notice/page/180927_00.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2018-0691",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23)",
"version": {
"version_data": [
{
"version_value": "Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23"
}
]
}
}
]
},
"vendor_name": "Softbank, NTT docomo, KDDI"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23) do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Fails to verify SSL certificates"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://www.au.com/information/notice_mobile/service/2018-002/",
"refsource": "MISC",
"url": "https://www.au.com/information/notice_mobile/service/2018-002/"
},
{
"name": "https://www.softbank.jp/mobile/info/personal/news/service/20180927a/",
"refsource": "MISC",
"url": "https://www.softbank.jp/mobile/info/personal/news/service/20180927a/"
},
{
"name": "JVN#37288228",
"refsource": "JVN",
"url": "http://jvn.jp/en/jp/JVN37288228/index.html"
},
{
"name": "https://www.nttdocomo.co.jp/info/notice/page/180927_00.html",
"refsource": "MISC",
"url": "https://www.nttdocomo.co.jp/info/notice/page/180927_00.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2018-0691",
"datePublished": "2018-11-15T15:00:00.000Z",
"dateReserved": "2017-11-27T00:00:00.000Z",
"dateUpdated": "2024-08-05T03:35:49.057Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2018-0517 (GCVE-0-2018-0517)
Vulnerability from cvelistv5 – Published: 2018-02-08 14:00 – Updated: 2024-08-05 03:28
VLAI
EPSS
VEX
Summary
Untrusted search path vulnerability in Anshin net security for Windows Version 16.0.1.44 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Severity
No CVSS data available.
CWE
- Untrusted search path vulnerability
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://jvn.jp/en/jp/JVN70615027/index.html | third-party-advisoryx_refsource_JVN |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| KDDI CORPORATION | Anshin net security for Windows |
Affected:
Version 16.0.1.44 and earlier
|
Date Public
2018-02-06 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T03:28:11.086Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "JVN#70615027",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "https://jvn.jp/en/jp/JVN70615027/index.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "Anshin net security for Windows",
"vendor": "KDDI CORPORATION",
"versions": [
{
"status": "affected",
"version": "Version 16.0.1.44 and earlier"
}
]
}
],
"datePublic": "2018-02-06T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Untrusted search path vulnerability in Anshin net security for Windows Version 16.0.1.44 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Untrusted search path vulnerability",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2018-02-08T13:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "JVN#70615027",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "https://jvn.jp/en/jp/JVN70615027/index.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2018-0517",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Anshin net security for Windows",
"version": {
"version_data": [
{
"version_value": "Version 16.0.1.44 and earlier"
}
]
}
}
]
},
"vendor_name": "KDDI CORPORATION"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability in Anshin net security for Windows Version 16.0.1.44 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "JVN#70615027",
"refsource": "JVN",
"url": "https://jvn.jp/en/jp/JVN70615027/index.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2018-0517",
"datePublished": "2018-02-08T14:00:00.000Z",
"dateReserved": "2017-11-27T00:00:00.000Z",
"dateUpdated": "2024-08-05T03:28:11.086Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}