CVE-2024-47044
CVE-2024-47044
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.3EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
26 sep 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION are vulnerable to insufficient access restrictions for Device Setting pages. If this vulnerability is exploited, an attacker who identified WAN-side IPv6 address may access the product's Device Setting page via WAN-side. Note that, the same products are also provided by NIPPON TELEGRAPH AND TELEPHONE WEST CORPORATION, but the vulnerability only affects products subscribed and used in NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION areas.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Productos afectados
NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION · Hikari Denwa router PR-400MINIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION · Hikari Denwa router RT-400MINIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION · Hikari Denwa router RV-440MINIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION · Home GateWay/Hikari Denwa router PR-500MI/RS-500MI/RT-500MINIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION · Home GateWay/Hikari Denwa router PR-600MI/RX-600MI¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://jvn.jp/en/jp/JVN78356367/https://web116.jp/ced/support/news/contents/2024/20240930.htmlhttps://web116.jp/ced/support/version/broadband/500mi/https://web116.jp/ced/support/version/broadband/600mi/https://web116.jp/ced/support/version/broadband/pr_400mi/https://web116.jp/ced/support/version/broadband/rt_400mi/https://web116.jp/ced/support/version/broadband/rv_440mi/