Published:2016/10/03  Last Updated:2016/10/03

JVN#46351856
Docomo L-04D mobile WiFi router vulnerable to cross-site request forgery

Overview

L-04D provided by NTT DOCOMO, INC. contains a cross-site request forgery vulnerability.

Products Affected

  • L-04D firmware version V10a and V10b

Description

L-04D provided by NTT DOCOMO, INC. is a wireless WiFi router.  L-04D contains a cross-site request forgery vulnerability in the the web management screen.

Impact

If a user views a malicious page while logged-in, unintended operations may be conducted.

Solution

Update the firmware
Update the firmware according to the information provided by NTT DOCOMO, INC.
 

Vendor Status

Vendor Status Last Update Vendor Notes
NTT DOCOMO, INC. Vulnerable 2016/10/03

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Base Score: 4.3
Attack Vector(AV) Physical (P) Local (L) Adjacent (A) Network (N)
Attack Complexity(AC) High (H) Low (L)
Privileges Required(PR) High (H) Low (L) None (N)
User Interaction(UI) Required (R) None (N)
Scope(S) Unchanged (U) Changed (C)
Confidentiality Impact(C) None (N) Low (L) High (H)
Integrity Impact(I) None (N) Low (L) High (H)
Availability Impact(A) None (N) Low (L) High (H)
CVSS v2 AV:N/AC:H/Au:N/C:N/I:P/A:N
Base Score: 2.6
Access Vector(AV) Local (L) Adjacent Network (A) Network (N)
Access Complexity(AC) High (H) Medium (M) Low (L)
Authentication(Au) Multiple (M) Single (S) None (N)
Confidentiality Impact(C) None (N) Partial (P) Complete (C)
Integrity Impact(I) None (N) Partial (P) Complete (C)
Availability Impact(A) None (N) Partial (P) Complete (C)

Credit

Atsuo Sakurai of Cyber Defense Institute, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2016-4854
JVN iPedia JVNDB-2016-000194