KDDI operates a portfolio of consumer and residential connectivity devices, primarily its Home Spot Cube line of wireless gateways and related messaging products. The vendor's vulnerabilities skew toward serious outcomes, with a meaningful share reaching critical severity, and cluster around OS command injection, out-of-bounds writes, and authentication or input-handling weaknesses that expose these edge devices to remote compromise. Defenders should prioritize patch assessment for internet-facing instances of Home Spot Cube and similar gateway products; current severity and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kddi over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-6005CRITICAL Smart TV Box firmware version prior to 1300 allows remote attackers to bypass access restriction to conduct arbitrary operations on the device without user's intent, such as instal | Sep 12, 2019 | 9.8 | 30 | NO | NO |
CVE-2022-33948HIGH HOME SPOT CUBE2 V102 contains an OS command injection vulnerability due to improper processing of data received from DHCP server. An adjacent attacker may execute an arbitrary OS c | Jul 4, 2022 | 8.8 | 28 | NO | NO |
CVE-2024-23978CRITICAL Heap-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. By processing invalid values, arbitrary code may be executed. Note that the affected products a | Feb 2, 2024 | 9.8 | 26 | NO | NO |
CVE-2018-0517HIGH Untrusted search path vulnerability in Anshin net security for Windows Version 16.0.1.44 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified | Feb 8, 2018 | 7.8 | 25 | NO | NO |
CVE-2017-2186HIGH HOME SPOT CUBE2 firmware V101 and earlier allows an attacker to bypass authentication to load malicious firmware via WebUI. | Jul 7, 2017 | 8.8 | 25 | NO | NO |
CVE-2017-2185HIGH HOME SPOT CUBE2 firmware V101 and earlier allows authenticated attackers to execute arbitrary OS commands via WebUI. | Jul 7, 2017 | 8.8 | 25 | NO | NO |
CVE-2024-21780HIGH Stack-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. Processing a specially crafted command may result in a denial of service (DoS) condition. Note | Feb 2, 2024 | 7.5 | 22 | NO | NO |
CVE-2018-0691MEDIUM Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior | Nov 15, 2018 | 5.9 | 22 | NO | NO |
CVE-2017-2184HIGH Buffer overflow in HOME SPOT CUBE2 firmware V101 and earlier allows an attacker to execute arbitrary code via WebUI. | Jul 7, 2017 | 8.8 | 22 | NO | NO |
CVE-2022-43543MEDIUM KDDI +Message App, NTT DOCOMO +Message App, and SoftBank +Message App contain a vulnerability caused by improper handling of Unicode control characters. +Message App displays text | Dec 21, 2022 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kddi.
Media articles that mention a CVE ID that affects a product developed by Kddi — matched by CVE ID, not by vendor name.