CVE-2016-1228: Ntt-East Pr-400mi Firmware

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability on NTT EAST Hikari Denwa routers with firmware PR-400MI, RT-400MI, and RV-440MI 07.00.1006 and earlier and NTT WEST Hikari Denwa routers with firmware PR-400MI, RT-400MI, and RV-440MI 07.00.1005 and earlier allows remote attackers to hijack the authentication of arbitrary users.

Affected products

  • Ntt-East Pr-400mi Firmware: version 07.00.1006 only
  • Ntt-East Rt-400mi Firmware: up to and including 07.00.1006
  • Ntt-East RV-440mi Firmware: up to and including 07.00.1006
  • Ntt-West Pr-400mi
  • Ntt-West Pr-400mi Firmware: up to and including 07.00.1005
  • Ntt-West Rt-400mi Firmware: up to and including 07.00.1005
  • Ntt-West RV-440mi Firmware: up to and including 07.00.1005

Published 2016-07-03. Last modified 2026-06-17.