Missing authentication for critical function in Wi-Fi AP UNIT allows a remote unauthenticated attacker to obtain sensitive information of the affected products. Affected products and versions are as follows: AC-PD-WAPU v1.05_B04 and earlier, AC-PD-WAPUM v1.05_B04 and earlier, AC-PD-WAPU-P v1.05_B04P and earlier, AC-PD-WAPUM-P v1.05_B04P and earlier, AC-WAPU-300 v1.00_B07 and earlier, AC-WAPUM-300 v1.00_B07 and earlier, AC-WAPU-300-P v1.00_B07 and earlier, and AC-WAPUM-300-P v1.00_B07 and earlier
Conclusion & alert: CVE-2023-31196 is rated Moderate Risk (48.4/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.84%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.91% | 0.84% | -0.07% |
| 2 | 2026-06-14 | 0.52% | 0.91% | +0.39% |
| 3 | 2026-04-09 | — | 0.52% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| inaba | ac-pd-wapu_firmware | <= 1.05_b04 | cpe:2.3:o:inaba:ac-pd-wapu_firmware:*:*:*:*:*:*:*:* |
| inaba | ac-pd-wapum_firmware | <= 1.05_b04 | cpe:2.3:o:inaba:ac-pd-wapum_firmware:*:*:*:*:*:*:*:* |
| inaba | ac-pd-wapu-p_firmware | <= 1.05_b04p | cpe:2.3:o:inaba:ac-pd-wapu-p_firmware:*:*:*:*:*:*:*:* |
| inaba | ac-pd-wapum-p_firmware | <= 1.05_b04p | cpe:2.3:o:inaba:ac-pd-wapum-p_firmware:*:*:*:*:*:*:*:* |
| inaba | ac-wapu-300_firmware | <= 1.00_b07 | cpe:2.3:o:inaba:ac-wapu-300_firmware:*:*:*:*:*:*:*:* |
| inaba | ac-wapum-300_firmware | <= 1.00_b07 | cpe:2.3:o:inaba:ac-wapum-300_firmware:*:*:*:*:*:*:*:* |
| inaba | ac-wapum-300-p_firmware | <= 1.00_b07 | cpe:2.3:o:inaba:ac-wapum-300-p_firmware:*:*:*:*:*:*:*:* |
| inaba | ac-wapu-300-p_firmware | <= 1.00_b07 | cpe:2.3:o:inaba:ac-wapu-300-p_firmware:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://jvn.jp/en/jp/JVN28412757/ | Mitigation Third Party Advisory |
| https://www.inaba.co.jp/abaniact/news/Wi-Fi_AP_UNIT%E3%81%AB%E3%81%8A%E3%81%91%E3%82%8B%E8%A4%87%E6%95%B0%E3%81%AE%E8%84%86%E5%BC%B1%E6%80%A7%E3%81%AB%E3%81%A4%E3%81%84%E3%81%A6.pdf | Vendor Advisory |