VYPR
Vendor

Rakuten

Products
13
CVEs
18
Across products
19
Status
Private

Products

13

Recent CVEs

18
  • CVE-2025-13476CriMar 5, 2026
    risk 0.64cvss 9.8epss 0.00

    Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking extension diversity, allowing Deep Packet Inspection (DPI) systems to trivially identify and block proxy traffic, undermining…

  • CVE-2022-29525CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 uses a hard-coded credential which may allow a remote unauthenticated attacker to log in with the root privilege and perform an arbitrary operation.

  • CVE-2024-48895HigNov 20, 2024
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is exploited, a remote authenticated attacker may execute an arbitrary OS command.

  • CVE-2019-18800HigNov 6, 2019
    risk 0.57cvss 8.8epss 0.02

    Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Viber protocol traffic is encrypted. TCP data packet 9 on port 4244 from the victim's device contains cleartext information such as the…

  • CVE-2025-68713HigJun 15, 2026
    risk 0.52cvss 8.0epss 0.00

    An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allows untrusted applications (with no permissions) to force arbitrary file downloads into the app's scoped storage. The resulting files…

  • CVE-2019-12569HigJun 3, 2019
    risk 0.52cvss 7.8epss 0.15

    A vulnerability in Viber before 10.7.0 for Desktop (Windows) could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI. An attacker could exploit this vulnerability by convincing a…

  • CVE-2026-68955HigSep 14, 2026
    risk 0.51cvss 7.8epss

    The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the…

  • CVE-2022-26834HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.02

    Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to obtain the information stored in the product because the product is set to accept HTTP connections from the WAN side by default.

  • CVE-2020-14049HigJun 22, 2020
    risk 0.49cvss 7.5epss 0.02

    Viber for Windows up to 13.2.0.39 does not properly quote its custom URI handler. A malicious website could launch Viber with arbitrary parameters, forcing a victim to send an NTLM authentication request, and either relay the request or capture the hash for offline password…

  • CVE-2022-28704HigJun 13, 2022
    risk 0.47cvss 7.2epss 0.03

    Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to log in with the root privilege and perform an arbitrary operation if the product is in its default settings in which is set to accept SSH connections from the WAN…

  • CVE-2019-6024MedDec 26, 2019
    risk 0.42cvss 6.5epss 0.02

    Rakuma App for Android version 7.15.0 and earlier, and for iOS version 7.16.4 and earlier allows an attacker to bypass authentication and obtain the user's authentication information via a malicious application created by the third party.

  • CVE-2025-55996MedSep 12, 2025
    risk 0.41cvss 6.3epss 0.00

    Viber Desktop 25.6.0 is vulnerable to HTML Injection via the text parameter of the message compose/forward interface

  • CVE-2024-41918MedAug 29, 2024
    risk 0.40cvss 6.1epss 0.00

    'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable to improper authorization in handler for custom URL scheme. An arbitrary site may be displayed on the WebView of the product via Intent from another application…

  • CVE-2018-3987MedFeb 13, 2020
    risk 0.36cvss 5.5epss 0.00

    An exploitable information disclosure vulnerability exists in the 'Secret Chats' functionality of Rakuten Viber on Android 9.3.0.6. The 'Secret Chats' functionality allows a user to delete all traces of a chat either by using a time trigger or by direct request. There is a bug…

  • CVE-2023-40282MedAug 23, 2023
    risk 0.35cvss 5.4epss 0.00

    Improper authentication vulnerability in Rakuten WiFi Pocket all versions allows a network-adjacent attacker to log in to the product's Management Screen. As a result, sensitive information may be obtained and/or the settings may be changed.

  • CVE-2024-52033MedNov 20, 2024
    risk 0.34cvss 5.3epss 0.00

    Exposure of sensitive system information to an unauthorized control sphere issue exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is exploited, a remote unauthenticated attacker may obtain information of the other devices connected through…

  • CVE-2024-47865MedNov 20, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing authentication for critical function vulnerability exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is exploited, a remote unauthenticated attacker may update or downgrade the firmware on the device.

  • CVE-2014-6907Oct 4, 2014
    risk 0.00cvss epss 0.00

    The Rakuten Install (aka co.jp.rakuten.installapp) application 1.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.