CVE-2023-40796
- EPSS 0.11%
- Veröffentlicht 25.08.2023 16:15:08
- Zuletzt bearbeitet 21.11.2024 08:20:08
Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call.
CVE-2022-48070
- EPSS 1%
- Veröffentlicht 27.01.2023 15:15:10
- Zuletzt bearbeitet 28.03.2025 16:15:23
Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function.
CVE-2022-48071
- EPSS 0.14%
- Veröffentlicht 27.01.2023 15:15:10
- Zuletzt bearbeitet 28.03.2025 16:15:23
Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.
CVE-2022-48072
- EPSS 1%
- Veröffentlicht 27.01.2023 15:15:10
- Zuletzt bearbeitet 28.03.2025 16:15:23
Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function.
CVE-2022-48073
- EPSS 0.14%
- Veröffentlicht 27.01.2023 15:15:10
- Zuletzt bearbeitet 28.03.2025 16:15:24
Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext.
CVE-2022-25218
- EPSS 1.52%
- Veröffentlicht 10.03.2022 17:47:02
- Zuletzt bearbeitet 21.11.2024 06:51:49
The use of the RSA algorithm without OAEP, or any other padding scheme, in telnetd_startup, allows an unauthenticated attacker on the local area network to achieve a significant degree of control over the "plaintext" to which an arbitrary blob of cip...
CVE-2022-25219
- EPSS 0.15%
- Veröffentlicht 10.03.2022 17:47:02
- Zuletzt bearbeitet 21.11.2024 06:51:49
A null byte interaction error has been discovered in the code that the telnetd_startup daemon uses to construct a pair of ephemeral passwords that allow a user to spawn a telnet service on the router, and to ensure that the telnet service persists up...
CVE-2022-25214
- EPSS 1.25%
- Veröffentlicht 10.03.2022 17:47:01
- Zuletzt bearbeitet 21.11.2024 06:51:49
Improper access control on the LocalClientList.asp interface allows an unauthenticated remote attacker to obtain sensitive information concerning devices on the local area network, including IP and MAC addresses. Improper access control on the wirele...
CVE-2022-25215
- EPSS 0.39%
- Veröffentlicht 10.03.2022 17:47:01
- Zuletzt bearbeitet 21.11.2024 06:51:49
Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacker to add (or remove) client MAC addresses to (or from) a list of banned hosts. Clients with those MAC addresses are then prevented from accessing eith...
CVE-2022-25217
- EPSS 0.05%
- Veröffentlicht 10.03.2022 17:47:01
- Zuletzt bearbeitet 21.11.2024 06:51:49
Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network to obtain a root shell on the device over telnet. The builds of telnetd_startup included in the version 22.5.9.163 of the K2 firmwa...