CVE-2016-1138
CRLF injection vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to inject arbitrary HTTP headers via unspecified vectors.
Date published : 2016-01-30
http://www.au.kddi.com/mobile/service/smartphone/wifi/homespot/#anc06