VYPR

K2

by Phicomm

CVEs (5)

  • CVE-2017-11495CriJul 20, 2017
    risk 0.64cvss 9.8epss 0.03

    PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; alternatively, the attacker can leverage unauthenticated access to this script to trigger a reboot via an ifType=reboot action.

  • CVE-2019-19117HigNov 18, 2019
    risk 0.58cvss 8.8epss 0.05

    /usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute any command via shell metacharacters in the cgi-bin/luci autoUpTime parameter.

  • CVE-2023-40796HigAug 25, 2023
    risk 0.51cvss 7.8epss 0.01

    Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call.

  • CVE-2022-48070HigJan 27, 2023
    risk 0.51cvss 7.8epss 0.01

    Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function.

  • CVE-2022-48071HigJan 27, 2023
    risk 0.49cvss 7.5epss 0.00

    Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.