Home/Product/phicomm k2 firmware
Product

phicomm k2 firmware

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-40796
all versions
Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call.
7.8HIGH
CVE-2022-48073
all versions
Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext.
7.5HIGH
CVE-2022-48072
all versions
Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic u
7.8HIGH
CVE-2022-48071
all versions
Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.
7.5HIGH
CVE-2022-48070
all versions
Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic
7.8HIGH
CVE-2022-25219
<= 22.5.9.163
A null byte interaction error has been discovered in the code that the telnetd_startup daemon uses to construct a pair of ephemera
8.4HIGH
CVE-2022-25218
<= 22.5.9.163
The use of the RSA algorithm without OAEP, or any other padding scheme, in telnetd_startup, allows an unauthenticated attacker on
8.1HIGH
CVE-2022-25217
<= 22.5.9.163
Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network to obtain a
7.8HIGH
CVE-2022-25215
<= 22.5.9.163
Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacker to add (or remove) client MA
5.3MEDIUM
CVE-2022-25214
<= 22.5.9.163
Improper access control on the LocalClientList.asp interface allows an unauthenticated remote attacker to obtain sensitive informa
7.4HIGH
CVE-2022-25213
<= 22.5.9.163
Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical access to obta
6.8MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin