FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors.
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
Link | Tags |
---|---|
http://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000090.html | third party advisory vdb entry |
https://jvn.jp/en/jp/JVN46372675/index.html | third party advisory vdb entry |
http://www.toshiba-personalstorage.net/news/20170516a.htm | vendor advisory |