CVE-2016-4863

MEDIUM

Toshiba Flashair < 1.00.03 - Authentication Bypass

Title source: rule

Description

The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later, FlashAir SD-WE series Class 10 model W-03, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir II Class 10 model W-02 series with firmware version 2.00.02 and later, FlashAir III Class 10 model W-03 series, FlashAir Class 6 model with firmware version 1.00.04 and later, FlashAir W-02 series Class 10 model with firmware version 2.00.02 and later, FlashAir W-03 series Class 10 model does not require authentication on accepting a connection from STA side LAN when "Internet pass-thru Mode" is enabled, which allows attackers with access to STA side LAN can obtain files or data.

Scores

CVSS v3 4.3
EPSS 0.0012
EPSS Percentile 30.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-287
Status published
Products (9)
toshiba/flashair < 1.00.03
Toshiba/FlashAir SD-WD/WC series Class 6 model < firmware version 1.00.04 and later
Toshiba/FlashAir SD-WD/WC series Class 10 model W-02 < firmware version 2.00.02 and later
Toshiba/FlashAir SD-WE series Class 10 model W-03 < all firmware versions
Toshiba/FlashAir Class 6 model < firmware version 1.00.04 and later
Toshiba/FlashAir II Class 10 model W-02 series < firmware version 2.00.02 and later
Toshiba/FlashAir III Class 10 model W-03 series < all firmware versions
Toshiba/FlashAir W-02 series Class 10 model < firmware version 2.00.02 and later
Toshiba/FlashAir W-03 series Class 10 model < all firmware versions
Published May 22, 2017
Tracked Since Feb 18, 2026