CVE-2016-1138
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/01/2016
Last modified:
12/04/2025
Description
CRLF injection vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to inject arbitrary HTTP headers via unspecified vectors.
Impact
Base Score 3.x
4.70
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:kddi:home_spot_cube_firmware:2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:h:kddi:home_spot_cube:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://jvn.jp/en/jp/JVN54686544/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000009
- http://www.au.kddi.com/mobile/service/smartphone/wifi/homespot/#anc06
- http://jvn.jp/en/jp/JVN54686544/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000009
- http://www.au.kddi.com/mobile/service/smartphone/wifi/homespot/#anc06



