[Japanese]

JVNDB-2012-000051

Logitec LAN-W300N/R series fails to restrict access permissions

Overview

Logitec LAN-W300N/R series contain an issue where access permissions are not restricted.

The LAN-W300N/R series are wireless LAN routers. Logitec LAN-W300N/R series contain an issue where access permissions are not restricted.

Jin Sawada, Keisuke Okazaki, Naoto Katsumi of Security Engineering Laboratory, IT Security Center(ISEC), IPA reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

Base Metrics: 7.5 (High) [IPA Score]
  • Access Vector: Network
  • Access Complexity: Low
  • Authentication: None
  • Confidentiality Impact: Partial
  • Integrity Impact: Partial
  • Availability Impact: Partial

Affected Products


Logitec Corp.
  • LAN-W300N/R firmware version 2.17

For more information, refer to the developer's website.
Impact

An attacker that can access the product may log in with administrative privileges. As a result, settings may be changed or altered by the attacker who logged in to LAN-W300N/R.
Solution

[Update the software]
Update to the latest version according to the information provided by the developer.
Vendor Information

Logitec Corp.
CWE (What is CWE?)

  1. Permissions(CWE-264) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2012-1250
References

  1. JVN : JVN#85934986
  2. National Vulnerability Database (NVD) : CVE-2012-1250
  3. IPA SECURITY ALERTS : Security Alert for Vulnerability in LAN-W300N/R Series
  4. JPCERT REPORT : JPCERT-AT-2012-0017 (Japanese Only)
  5. Related document : OCN [Important] Security Notice for Logitec wireless LAN router (Japanese Only)
Revision History

[2012/05/25]
  Web page was published