Inaba Denki Sangyo Wi-Fi AP Unit AC-WPS-11ac Series Cross-Site Request Forgery Vulnerability

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in the Wi-Fi AP UNIT 'AC-WPS-11ac series' by Inaba Denki Sangyo Co., Ltd. This vulnerability affects all versions through v2.0.03P. When a user, logged into the device, views a malicious webpage, it may trigger unintended actions on the device.

Impact

Exploitation of this vulnerability could lead to unauthorized operations being performed on the affected device, potentially allowing for changes to the device's settings or internal data.

Remediation

Users are advised to update the device's firmware to the latest version, v2.0.06.13P. If the firmware update is not feasible, the manufacturer recommends implementing certain workarounds, such as prohibiting access to the web UI from WAN or wireless connections, and registering the MAC addresses of permitted wireless devices.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.