cbcvebase.

Phicomm K2 Firmware vulnerabilities

13 known vulnerabilities affecting phicomm/k2_firmware.

Total CVEs
13
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2017-11495P2CRITICALCVSS 9.8≤ 22.5.11.52017-07-20
CVE-2017-11495 [CRITICAL] CWE-20 CVE-2017-11495: PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; alternatively, the attacker can leverage unauthenticated access to this script to trigger a reboot via an ifType=reboot action.
nvd
CVE-2019-19117P3HIGHCVSS 8.8v22.5.9.1632019-11-18
CVE-2019-19117 [HIGH] CWE-78 CVE-2019-19117: /usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows /usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute any command via shell metacharacters in the cgi-bin/luci autoUpTime parameter.
nvd
CVE-2022-25218P3HIGHCVSS 8.1≤ 22.5.9.1632022-03-10
CVE-2022-25218 [HIGH] CWE-327 CVE-2022-25218: The use of the RSA algorithm without OAEP, or any other padding scheme, in telnetd_startup, allows a The use of the RSA algorithm without OAEP, or any other padding scheme, in telnetd_startup, allows an unauthenticated attacker on the local area network to achieve a significant degree of control over the "plaintext" to which an arbitrary blob of ciphertext will be decrypted by OpenSSL's RSA_public_decrypt() function. This weakness allows the attacker
nvd
CVE-2022-25214P3HIGHCVSS 7.4≤ 22.5.9.1632022-03-10
CVE-2022-25214 [HIGH] CVE-2022-25214: Improper access control on the LocalClientList.asp interface allows an unauthenticated remote attack Improper access control on the LocalClientList.asp interface allows an unauthenticated remote attacker to obtain sensitive information concerning devices on the local area network, including IP and MAC addresses. Improper access control on the wirelesssetup.asp interface allows an unauthenticated remote attacker to obtain the WPA passphrases for the 2.4GHz an
nvd
CVE-2022-48072P3HIGHCVSS 7.8v22.6.3.202023-01-27
CVE-2022-48072 [HIGH] CWE-78 CVE-2022-48072: Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTim Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function.
nvd
CVE-2022-48070P3HIGHCVSS 7.8v22.6.534.2632023-01-27
CVE-2022-48070 [HIGH] CWE-78 CVE-2022-48070: Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpT Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function.
nvd
CVE-2022-25217P3HIGHCVSS 7.8≤ 22.5.9.1632022-03-10
CVE-2022-25217 [HIGH] CWE-798 CVE-2022-25217: Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network to obtain a root shell on the device over telnet. The builds of telnetd_startup included in the version 22.5.9.163 of the K2 firmware, and version 32.1.15.93 of the K3C firmware (possibly amongst many other releases) included both the
nvd
CVE-2022-25219P3HIGHCVSS 8.4≤ 22.5.9.1632022-03-10
CVE-2022-25219 [HIGH] CVE-2022-25219: A null byte interaction error has been discovered in the code that the telnetd_startup daemon uses t A null byte interaction error has been discovered in the code that the telnetd_startup daemon uses to construct a pair of ephemeral passwords that allow a user to spawn a telnet service on the router, and to ensure that the telnet service persists upon reboot. By means of a crafted exchange of UDP packets, an unauthenticated attacker on the local network can
nvd
CVE-2023-40796P3HIGHCVSS 7.8v22.6.529.2162023-08-25
CVE-2023-40796 [HIGH] CWE-77 CVE-2023-40796: Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the functio Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call.
nvd
CVE-2022-48073P3HIGHCVSS 7.5v22.6.534.2632023-01-27
CVE-2022-48073 [HIGH] CWE-312 CVE-2022-48073: Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext. Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext.
nvd
CVE-2022-48071P3HIGHCVSS 7.5v22.6.534.2632023-01-27
CVE-2022-48071 [HIGH] CWE-312 CVE-2022-48071: Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext. Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.
nvd
CVE-2022-25213P4MEDIUMCVSS 6.8≤ 22.5.9.1632022-03-10
CVE-2022-25213 [MEDIUM] CWE-798 CVE-2022-25213: Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacke Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical access to obtain a root shell via an unprotected UART port on the device. The same port exposes an unauthenticated Das U-Boot BIOS shell.
nvd
CVE-2022-25215P4MEDIUMCVSS 5.3≤ 22.5.9.1632022-03-10
CVE-2022-25215 [MEDIUM] CVE-2022-25215: Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacke Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacker to add (or remove) client MAC addresses to (or from) a list of banned hosts. Clients with those MAC addresses are then prevented from accessing either the WAN or the router itself.
nvd
Phicomm K2 Firmware vulnerabilities | cvebase