Phicomm
Phicomm K2 Firmware: vulnerabilidades y CVE
Phicomm K2 Firmware tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-40796 | Alta (7.8) | 0.92% | — | 25 ago 2023 | Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call. |
| CVE-2022-48073 | Alta (7.5) | 0.45% | — | 27 ene 2023 | Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext. |
| CVE-2022-48072 | Alta (7.8) | 0.90% | — | 27 ene 2023 | Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function. |
| CVE-2022-48071 | Alta (7.5) | 0.44% | — | 27 ene 2023 | Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext. |
| CVE-2022-48070 | Alta (7.8) | 0.90% | — | 27 ene 2023 | Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function. |
| CVE-2022-25219 | Alta (8.4) | 0.77% | — | 10 mar 2022 | A null byte interaction error has been discovered in the code that the telnetd_startup daemon uses to construct a pair of ephemeral passwords that allow a user to spawn a telnet service on the router, and to ensure that… |
| CVE-2022-25218 | Alta (8.1) | 0.99% | — | 10 mar 2022 | The use of the RSA algorithm without OAEP, or any other padding scheme, in telnetd_startup, allows an unauthenticated attacker on the local area network to achieve a significant degree of control over the "plaintext" to… |
| CVE-2022-25217 | Alta (7.8) | 0.33% | — | 10 mar 2022 | Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network to obtain a root shell on the device over telnet. The builds of telnetd_startup included in the… |
| CVE-2022-25215 | Media (5.3) | 1.1% | — | 10 mar 2022 | Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacker to add (or remove) client MAC addresses to (or from) a list of banned hosts. Clients with those MAC addresses are… |
| CVE-2022-25214 | Alta (7.4) | 1.5% | — | 10 mar 2022 | Improper access control on the LocalClientList.asp interface allows an unauthenticated remote attacker to obtain sensitive information concerning devices on the local area network, including IP and MAC addresses.… |
| CVE-2022-25213 | Media (6.8) | 0.37% | — | 10 mar 2022 | Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical access to obtain a root shell via an unprotected UART port on the device. The same port exposes an… |