CVE-2022-28704 - CVE House
Back to Database
Status published High CVE-2022-28704

Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or...

Vulnerability Description

Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to log in with the root privilege and perform an arbitrary operation if the product is in its default settings in which is set to accept SSH connections from the WAN side, and is also connected to the Internet with the authentication information unchanged from the default settings.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-28704

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Rakuten Mobile, Inc.

View all reports →

Affected Software

Rakuten Casa
Vulnerable Versions:
version AP_F_V1_4_1 or AP_F_V2_0_0

Timeline

Official Publish: June 13th, 2022
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.