CVE-2013-4708: Iij seil%2fb1 Firmware

Medium severity, CVSS 4.0. EPSS: 1.3% chance of exploitation in the next 30 days.

The PPP Access Concentrator (PPPAC) in Internet Initiative Japan Inc. SEIL/x86 1.00 through 2.80, SEIL/X1 1.00 through 4.30, SEIL/X2 1.00 through 4.30, SEIL/B1 1.00 through 4.30, SEIL/Turbo 1.80 through 2.15, and SEIL/neu 2FE Plus 1.80 through 2.15 generates predictable random numbers, which allows remote attackers to bypass RADIUS authentication by sniffing RADIUS traffic.

Affected products

  • Iij seil%2fb1 Firmware: version 1.00 only; version 4.30 only
  • Iij seil%2fneu 2fe Plus Firmware: version 1.80 only; version 2.05 only; version 2.15 only
  • Iij seil%2fturbo Firmware: version 1.80 only; version 2.05 only; version 2.15 only
  • Iij seil%2fx1 Firmware: version 1.00 only; version 4.30 only
  • Iij seil%2fx2 Firmware: version 1.00 only; version 4.30 only
  • Iij seil%2fx86 Firmware: version 1.00 only; version 2.80 only
  • Iij seil/b1
  • Iij Seil/neu 2fe Plus
  • Iij Seil/turbo
  • Iij seil/x1
  • Iij seil/x2
  • Iij seil/x86

Published 2013-10-01. Last modified 2026-06-16.