JVN#13159997
Multiple I-O DATA DEVICE wireless LAN routers default configuration does not set authentication
Critical
Overview
The web administration interface for the WN-APG/R-Series and WN-WAPG/R-Series wireless LAN routers from I-O DATA DEVICE disables authentication in the default configuration.
Products Affected
- WN-APG/R firmware version 1.05J/W and earlier
- WN-APG/R-S firmware version 1.05J/W and earlier
- WN-WAPG/R firmware version 2.04 and earlier
- WN-WAPG/R-S firmware version 2.04 and earlier
Description
The authentication for the web administration interface for the WN-APG/R-Series and WN-WAPG/R-Series wireless LAN routers from I-O DATA DEVICE is disabled in the default configuration. This vulnerability may allow a remote attacker to access the web administration interface without authentication.
Impact
A remote attacker could change the configuration of vulnerable routers or obtain configuration information.
Solution
Update the Software
Update to the latest firmware provided by the vendor.
For more information, refer to the vendor's website.
Change the Setting
For more information, refer to the vendor's website.
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Analyzed on 2008.03.18 Critical
Measures | Conditions | Severity |
---|---|---|
Access Required | Routed - can be attacked over the Internet using packets |
|
Authentication | None - anonymous or no authentication (IP addresses do not count) |
|
User Interaction Required | None - the vulnerability can be exploited without an honest user taking any action |
|
Exploit Complexity | Low - little to no expertise and/or luck required to exploit (cross-site scripting) |
|
Credit
Hirotaka Katagiri reported this vulnerability to IPA.
JPCERT/CC coordinated with the vendors under Information Security Early Warning Partnership.
Other Information
JPCERT Alert | |
JPCERT Reports | |
CERT Advisory | |
CPNI Advisory | |
TRnotes | |
CVE | |
JVN iPedia |
JVNDB-2008-000017 |
Update History
- 2008/05/21
- JVN English site opened and the first English advisory of this issue was published.
- 2008/07/17
- Information under the section "References" was added.