CVE-2022-26834 is an improper access control vulnerability affecting Rakuten Casa versions AP_F_V1_4_1 and AP_F_V2_0_0, allowing remote attackers to obtain stored information due to default HTTP WAN connections. This vulnerability has a CVSS score of 7.5 (HIGH), indicating a severe risk with network-based attacks requiring no user interaction or privileges, leading to high confidentiality impact. There is currently no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
ap_f_v1_4_1CPE matchmatch criteria | cpe:2.3:a:rakuten:casa:ap_f_v1_4_1:*:*:*:*:*:*:* | ||
ap_f_v2_0_0CPE matchmatch criteria | cpe:2.3:a:rakuten:casa:ap_f_v2_0_0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.