VYPR
High severity7.5NVD Advisory· Published Jun 13, 2022· Updated Jun 17, 2026

CVE-2022-26834

CVE-2022-26834

Description

Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to obtain the information stored in the product because the product is set to accept HTTP connections from the WAN side by default.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Rakuten Mobile, Inc./Rakuten Casav5
    Range: version AP_F_V1_4_1 or AP_F_V2_0_0
  • Rakuten/Casallm-create3 versions
    AP_F_V1_4_1 or AP_F_V2_0_0+ 2 more
    • (no CPE)range: AP_F_V1_4_1 or AP_F_V2_0_0
    • cpe:2.3:a:rakuten:casa:ap_f_v1_4_1:*:*:*:*:*:*:*
    • cpe:2.3:a:rakuten:casa:ap_f_v2_0_0:*:*:*:*:*:*:*
  • Range: AP_F_V1_4_1 or AP_F_V2_0_0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.