Missing authentication for critical function vulnerability exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is exploited, a remote unauthenticated attacker may update or downgrade the firmware on the device.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.