The WPS implementation on I-O DATA DEVICE WN-GDN/R3, WN-GDN/R3-C, WN-GDN/R3-S, and WN-GDN/R3-U devices does not limit PIN guesses, which allows remote attackers to obtain network access via a brute-force attack.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://jvn.jp/en/jp/JVN25674893/index.html | third party advisory vendor advisory |
http://jvndb.jvn.jp/jvndb/JVNDB-2016-000061 | third party advisory vendor advisory |
http://www.iodata.jp/support/information/2016/wn-gdnr3_bfa/ | vendor advisory |