CVE-2009-4409
Internet Initiative Japan SEIL/B1 <2.52 - Auth Bypass
Title source: llmDescription
The (1) CHAP and (2) MS-CHAP-V2 authentication capabilities in the PPP Access Concentrator (PPPAC) function in Internet Initiative Japan SEIL/B1 firmware 1.00 through 2.52 use the same challenge for each authentication attempt, which allows remote attackers to bypass authentication via a replay attack.
References (6)
Scores
EPSS
0.0029
EPSS Percentile
52.1%
Classification
CWE
CWE-287
Status
draft
Affected Products (11)
iij/seil\/b1
iij/seil\/b1
iij/seil\/b1
iij/seil\/b1
iij/seil\/b1
iij/seil\/b1
iij/seil\/b1
iij/seil\/b1
iij/seil\/b1
iij/seil\/b1
iij/seil\/b1
Timeline
Published
Dec 23, 2009
Tracked Since
Feb 18, 2026