Incorrect privilege assignment vulnerability in the WEB UI (the setting page) exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a remote attacker who can log in to the product may alter the settings without appropriate privileges.
CVE ID: CVE-2025-23407
CVSS Base Severity: MEDIUM
CVSS Base Score: 4.3
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Vendor: Inaba Denki Sangyo Co., Ltd., Inaba Denki Sangyo Co., Ltd., Inaba Denki Sangyo Co., Ltd., Inaba Denki Sangyo Co., Ltd., Inaba Denki Sangyo Co., Ltd., Inaba Denki Sangyo Co., Ltd.
Product: AC-WPS-11ac, AC-WPS-11ac-P, AC-WPSM-11ac, AC-WPSM-11ac-P, AC-PD-WPS-11ac, AC-PD-WPS-11ac-P
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 10.23% (scored less or equal to compared to others)
EPSS Date: 2025-04-21 (when was this score calculated)