The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.15.1 and earlier for Android and 1.13.0 and earlier for iOS allows man-in-the-middle attackers to obtain API access via unspecified vectors.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://jvn.jp/en/jp/JVN46888319/278948/index.html | vendor advisory |
https://play.google.com/store/apps/details?id=com.nttbp.jfw | |
http://jvn.jp/en/jp/JVN46888319/index.html | third party advisory vendor advisory |
https://itunes.apple.com/app/japan-connected-free-wi-fi/id810838196 | |
http://jvndb.jvn.jp/jvndb/JVNDB-2016-000076 | third party advisory vendor advisory |