CVE-2024-47044
Multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION are vulnerable to insufficient access restrictions for Device Setting pages. If this vulnerability is exploited, an attacker who identified WAN-side IPv6 address may access the product's Device Setting page via WAN-side. Note that, the same products are also provided by NIPPON TELEGRAPH AND TELEPHONE WEST CORPORATION, but the vulnerability only affects products subscribed and used in NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION areas.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.43%
- Percentil entre todas las CVEs puntuadas: 35
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-451
Referencias
- https://jvn.jp/en/jp/JVN78356367/
- https://web116.jp/ced/support/news/contents/2024/20240930.html
- https://web116.jp/ced/support/version/broadband/500mi/
- https://web116.jp/ced/support/version/broadband/600mi/
- https://web116.jp/ced/support/version/broadband/pr_400mi/
- https://web116.jp/ced/support/version/broadband/rt_400mi/
- https://web116.jp/ced/support/version/broadband/rv_440mi/
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-47044",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-47044",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-09-26T18:32:49.475278Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "vultures@jpcert.or.jp",
"affectedData": [
{
"vendor": "NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION",
"product": "Hikari Denwa router RT-400MI",
"versions": [
{
"status": "affected",
"version": "Ver.09.00.0015 and earlier"
}
]
},
{
"vendor": "NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION",
"product": "Hikari Denwa router PR-400MI",
"versions": [
{
"status": "affected",
"version": "Ver.09.00.0015 and earlier"
}
]
},
{
"vendor": "NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION",
"product": "Hikari Denwa router RV-440MI",
"versions": [
{
"status": "affected",
"version": "Ver.09.00.0015 and earlier"
}
]
},
{
"vendor": "NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION",
"product": "Home GateWay/Hikari Denwa router PR-500MI/RS-500MI/RT-500MI",
"versions": [
{
"status": "affected",
"version": "Ver.08.00.0004 and earlier"
}
]
},
{
"vendor": "NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION",
"product": "Home GateWay/Hikari Denwa router PR-600MI/RX-600MI",
"versions": [
{
"status": "affected",
"version": "Ver.01.00.0008 and earlier"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:o:ntt-east:pr-400mi_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:ntt-east:rt-400mi_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:ntt-east:rv-440mi_firmware:-:*:*:*:*:*:*:*"
],
"vendor": "ntt-east",
"product": "rv-440mi_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "09.00.0015"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:ntt-east:pr-500mi_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:ntt-east:rs-500mi_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:ntt-east:rt-500mi_firmware:-:*:*:*:*:*:*:*"
],
"vendor": "ntt-east",
"product": "rt-500mi_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "08.00.0004"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:ntt-east:pr-600mi_firmware:*:*:*:*:*:*:*:*",
"cpe:2.3:o:ntt-east:rx-600mi_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "ntt-east",
"product": "rx-600mi_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "01.00.0008"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-09-26T09:15:02.317",
"references": [
{
"url": "https://jvn.jp/en/jp/JVN78356367/",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://web116.jp/ced/support/news/contents/2024/20240930.html",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://web116.jp/ced/support/version/broadband/500mi/",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://web116.jp/ced/support/version/broadband/600mi/",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://web116.jp/ced/support/version/broadband/pr_400mi/",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://web116.jp/ced/support/version/broadband/rt_400mi/",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://web116.jp/ced/support/version/broadband/rv_440mi/",
"source": "vultures@jpcert.or.jp"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "vultures@jpcert.or.jp",
"description": [
{
"lang": "en",
"value": "CWE-451"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION are vulnerable to insufficient access restrictions for Device Setting pages. If this vulnerability is exploited, an attacker who identified WAN-side IPv6 address may access the product's Device Setting page via WAN-side. Note that, the same products are also provided by NIPPON TELEGRAPH AND TELEPHONE WEST CORPORATION, but the vulnerability only affects products subscribed and used in NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION areas."
},
{
"lang": "es",
"value": "Varios enrutadores Home GateWay/Hikari Denwa proporcionados por NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION son vulnerables a restricciones de acceso insuficientes para las páginas de configuración de dispositivos. Si se explota esta vulnerabilidad, un atacante que identifique la dirección IPv6 del lado WAN puede acceder a la página de configuración de dispositivos del producto a través del lado WAN. Tenga en cuenta que NIPPON TELEGRAPH AND TELEPHONE WEST CORPORATION también proporciona los mismos productos, pero la vulnerabilidad solo afecta a los productos suscritos y utilizados en las áreas de NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION."
}
],
"lastModified": "2026-06-17T07:56:26.497",
"sourceIdentifier": "vultures@jpcert.or.jp"
}