CVE-2015-5630
Description
An XSS vulnerability in the Japan Connected-free Wi-Fi app allows attackers to inject arbitrary scripts via a crafted SSID when the device connects to a malicious access point.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An XSS vulnerability in the Japan Connected-free Wi-Fi app allows attackers to inject arbitrary scripts via a crafted SSID when the device connects to a malicious access point.
Vulnerability
A cross-site scripting (XSS) vulnerability exists in the Japan Connected-free Wi-Fi application provided by NTT Broadband Platform, Inc. The application fails to properly sanitize SSID strings before displaying them. Affected versions include Android 1.6.0 and earlier, and iOS 1.0.2 and earlier [1][2]. The flaw is categorized as an Improper Input Validation issue (CWE-20) [2].
Exploitation
An attacker must set up a wireless access point with a crafted SSID containing malicious script. When a device running a vulnerable version of the app connects to that access point, the app displays the SSID, causing the embedded script to execute in the context of the application [1][2]. No authentication or user interaction beyond connecting to the Wi-Fi network is required.
Impact
Successful exploitation allows the attacker to execute arbitrary web script or HTML within the app's display context. This can lead to information disclosure, session hijacking, or other client-side attacks depending on the capabilities available to the app's web view [1][2].
Mitigation
Users should update the application to the latest version provided by the developer for both Android (via Google Play) and iOS (via the App Store) [1][2]. The vendor announced the fix on September 11, 2015 [1][2]. The CVSS v2 base score is 5.4 (Medium) with adjacent network access vector [2].
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3cpe:2.3:a:ntt-bp:japan_connected-free_wi-fi:*:*:*:*:*:android:*:*+ 2 more
- cpe:2.3:a:ntt-bp:japan_connected-free_wi-fi:*:*:*:*:*:android:*:*range: <=1.6.0
- cpe:2.3:a:ntt-bp:japan_connected-free_wi-fi:*:*:*:*:*:iphone_os:*:*range: <=1.0.2
- (no CPE)range: <=1.6.0 (Android) / <=1.0.2 (iOS)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- itunes.apple.com/en/app/japan-connected-free-wi-fi/id810838196nvdPatch
- play.google.com/store/apps/detailsnvdPatch
- jvn.jp/en/jp/JVN41048401/index.htmlnvdVendor Advisory
- jvndb.jvn.jp/jvndb/JVNDB-2015-000116nvdVendor Advisory
News mentions
0No linked articles in our index yet.