Inaba Denki Sangyo Wi-Fi AP Unit Clickjacking Vulnerability

Vulnerability

A clickjacking vulnerability has been identified in the Wi-Fi AP UNIT 'AC-WPS-11ac series' by Inaba Denki Sangyo Co., Ltd. This issue affects users who are logged in and interact with content on a malicious page, potentially leading to unintended actions being performed. The vulnerability is present in all versions through v2.0.03P of the AC-WPS-11ac, AC-WPS-11ac-P, AC-WPSM-11ac, AC-WPSM-11ac-P, AC-PD-WPS-11ac, and AC-PD-WPS-11ac-P products.

Impact

Exploitation of this vulnerability allows for unintended operations to be performed on behalf of the user who is logged in.

Remediation

Users are advised to update the firmware to the latest version, v2.0.06.13P, available for all affected product variants. If updating is not possible, consider implementing recommended workarounds, such as restricting access to the WEB UI from WAN/Wireless connections and using a router with updated firmware.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.