Description
Missing authentication for critical function exists in Seiko Solutions SkyBridge series, which may allow a remote attacker to obtain or alter the setting information of the product or execute some critical functions without authentication, e.g., rebooting the product. Affected products and versions are as follows: SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, and SkyBridge BASIC MB-A130 firmware Ver. 1.4.1 and earlier
References (6)
Core 6
Core References
Third Party Advisory
https://jvn.jp/en/jp/JVN40604023/
Vendor Advisory
https://www.seiko-sol.co.jp/archives/73969/
Scores
CVSS v3
8.6
EPSS
0.0098
EPSS Percentile
57.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-306
Status
published
Products (2)
seiko-sol/skybridge_basic_mb-a130_firmware
< 1.4.1
seiko-sol/skybridge_mb-a200_firmware
< 01.00.05
Published
May 10, 2023
Tracked Since
Feb 18, 2026