Multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION are vulnerable to insufficient access restrictions for Device Setting pages. If this vulnerability is exploited, an attacker who identified WAN-side IPv6 address may access the product's Device Setting page via WAN-side. Note that, the same products are also provided by NIPPON TELEGRAPH AND TELEPHONE WEST CORPORATION, but the vulnerability only affects products subscribed and used in NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION areas.
History

Thu, 17 Oct 2024 01:45:00 +0000

Type Values Removed Values Added
References

Thu, 26 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Ntt-east
Ntt-east pr-400mi Firmware
Ntt-east pr-500mi Firmware
Ntt-east pr-600mi Firmware
Ntt-east rs-500mi Firmware
Ntt-east rt-400mi Firmware
Ntt-east rt-500mi Firmware
Ntt-east rv-440mi Firmware
Ntt-east rx-600mi Firmware
CPEs cpe:2.3:o:ntt-east:pr-400mi_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:ntt-east:pr-500mi_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:ntt-east:pr-600mi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ntt-east:rs-500mi_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:ntt-east:rt-400mi_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:ntt-east:rt-500mi_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:ntt-east:rv-440mi_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:ntt-east:rx-600mi_firmware:*:*:*:*:*:*:*:*
Vendors & Products Ntt-east
Ntt-east pr-400mi Firmware
Ntt-east pr-500mi Firmware
Ntt-east pr-600mi Firmware
Ntt-east rs-500mi Firmware
Ntt-east rt-400mi Firmware
Ntt-east rt-500mi Firmware
Ntt-east rv-440mi Firmware
Ntt-east rx-600mi Firmware
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Sep 2024 08:45:00 +0000

Type Values Removed Values Added
Description Multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION are vulnerable to insufficient access restrictions for Device Setting pages. If this vulnerability is exploited, an attacker who identified WAN-side IPv6 address may access the product's Device Setting page via WAN-side. Note that, the same products are also provided by NIPPON TELEGRAPH AND TELEPHONE WEST CORPORATION, but the vulnerability only affects products subscribed and used in NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION areas.
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2024-09-26T08:34:30.347Z

Updated: 2024-10-17T01:33:49.083Z

Reserved: 2024-09-17T04:53:47.412Z

Link: CVE-2024-47044

cve-icon Vulnrichment

Updated: 2024-09-26T18:33:10.450Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-26T09:15:02.317

Modified: 2024-10-17T02:15:02.840

Link: CVE-2024-47044

cve-icon Redhat

No data.