CVE-2009-4409

Internet Initiative Japan SEIL/B1 <2.52 - Auth Bypass

Title source: llm

Description

The (1) CHAP and (2) MS-CHAP-V2 authentication capabilities in the PPP Access Concentrator (PPPAC) function in Internet Initiative Japan SEIL/B1 firmware 1.00 through 2.52 use the same challenge for each authentication attempt, which allows remote attackers to bypass authentication via a replay attack.

Scores

EPSS 0.0029
EPSS Percentile 52.1%

Classification

CWE
CWE-287
Status draft

Affected Products (11)

iij/seil\/b1
iij/seil\/b1
iij/seil\/b1
iij/seil\/b1
iij/seil\/b1
iij/seil\/b1
iij/seil\/b1
iij/seil\/b1
iij/seil\/b1
iij/seil\/b1
iij/seil\/b1

Timeline

Published Dec 23, 2009
Tracked Since Feb 18, 2026