VYPR
Vendor

Rakuten

Products
8
CVEs
8
Across products
8
Status
Private

Products

8

Recent CVEs

8
  • CVE-2022-29525CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 uses a hard-coded credential which may allow a remote unauthenticated attacker to log in with the root privilege and perform an arbitrary operation.

  • CVE-2024-48895HigNov 20, 2024
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is exploited, a remote authenticated attacker may execute an arbitrary OS command.

  • CVE-2025-68713HigJun 15, 2026
    risk 0.52cvss 8.0epss 0.00

    An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allows untrusted applications (with no permissions) to force arbitrary file downloads into the app's scoped storage. The resulting files…

  • CVE-2022-26834HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to obtain the information stored in the product because the product is set to accept HTTP connections from the WAN side by default.

  • CVE-2023-40282MedAug 23, 2023
    risk 0.35cvss 5.4epss 0.00

    Improper authentication vulnerability in Rakuten WiFi Pocket all versions allows a network-adjacent attacker to log in to the product's Management Screen. As a result, sensitive information may be obtained and/or the settings may be changed.

  • CVE-2024-52033MedNov 20, 2024
    risk 0.34cvss 5.3epss 0.00

    Exposure of sensitive system information to an unauthorized control sphere issue exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is exploited, a remote unauthenticated attacker may obtain information of the other devices connected through…

  • CVE-2024-47865MedNov 20, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing authentication for critical function vulnerability exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is exploited, a remote unauthenticated attacker may update or downgrade the firmware on the device.

  • CVE-2014-6907Oct 4, 2014
    risk 0.00cvss epss 0.00

    The Rakuten Install (aka co.jp.rakuten.installapp) application 1.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.