JVN#13159997
			Multiple I-O DATA DEVICE wireless LAN routers default configuration does not set authentication
						
							
								Critical
							
						
						
			
			Overview
The web administration interface for the WN-APG/R-Series and WN-WAPG/R-Series wireless LAN routers from I-O DATA DEVICE disables authentication in the default configuration.
Products Affected
- WN-APG/R firmware version 1.05J/W and earlier
- WN-APG/R-S firmware version 1.05J/W and earlier
- WN-WAPG/R firmware version 2.04 and earlier
- WN-WAPG/R-S firmware version 2.04 and earlier
Description
The authentication for the web administration interface for the WN-APG/R-Series and WN-WAPG/R-Series wireless LAN routers from I-O DATA DEVICE is disabled in the default configuration. This vulnerability may allow a remote attacker to access the web administration interface without authentication.
Impact
A remote attacker could change the configuration of vulnerable routers or obtain configuration information.
Solution
										
						
							
							Update the Software
						
						
							
								Update to the latest firmware provided by the vendor.
For more information, refer to the vendor's website.
							
						
					
						
							
							Change the Setting
						
						
							
								For more information, refer to the vendor's website.
							
						
					
					
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Analyzed on 2008.03.18 Critical
| Measures | Conditions | Severity | 
|---|---|---|
| Access Required | Routed - can be attacked over the Internet using packets | 
 | 
| Authentication | None - anonymous or no authentication (IP addresses do not count) | 
 | 
| User Interaction Required | None - the vulnerability can be exploited without an honest user taking any action | 
 | 
| Exploit Complexity | Low - little to no expertise and/or luck required to exploit (cross-site scripting) | 
 | 
Credit
					Hirotaka Katagiri reported this vulnerability to IPA. 
JPCERT/CC coordinated with the vendors under Information Security Early Warning Partnership.
					
Other Information
| JPCERT Alert | |
| JPCERT Reports | |
| CERT Advisory | |
| CPNI Advisory | |
| TRnotes | |
| CVE | |
| JVN iPedia | JVNDB-2008-000017 | 
Update History
- 2008/05/21
- JVN English site opened and the first English advisory of this issue was published.
- 2008/07/17
- Information under the section "References" was added.

