First published: Mon May 22 2017(Updated: )
FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows default credentials to be set for wireless LAN connections to the product when enabling the PhotoShare function through a web browser.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Toshiba FlashAir | <=2.00.04 | |
Toshiba FlashAir | <=3.00.02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2162 has a medium severity level due to the potential for unauthorized access through default credentials.
To fix CVE-2017-2162, update to the latest version of the FlashAir memory card firmware that addresses the default credential vulnerability.
CVE-2017-2162 affects Toshiba FlashAir SDHC Memory Card models of the SD-WE Series V3.00.02 and earlier, and SD-WD/WC Series V2.00.04 and earlier.
CVE-2017-2162 allows attackers to gain unauthorized access to the device due to default credentials set for wireless LAN connections when PhotoShare is enabled.
Yes, CVE-2017-2162 can be easily exploited by anyone who knows the default credentials used for wireless connections.