K2
by Phicomm
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-11495 | Cri | 0.64 | 9.8 | 0.03 | Jul 20, 2017 | PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; alternatively, the attacker can leverage unauthenticated access to this script to trigger a reboot via an ifType=reboot action. | ||
| CVE-2019-19117 | Hig | 0.58 | 8.8 | 0.05 | Nov 18, 2019 | /usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute any command via shell metacharacters in the cgi-bin/luci autoUpTime parameter. | ||
| CVE-2023-40796 | Hig | 0.51 | 7.8 | 0.01 | Aug 25, 2023 | Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call. | ||
| CVE-2022-48070 | Hig | 0.51 | 7.8 | 0.01 | Jan 27, 2023 | Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function. | ||
| CVE-2022-48071 | Hig | 0.49 | 7.5 | 0.00 | Jan 27, 2023 | Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext. |
- risk 0.64cvss 9.8epss 0.03
PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; alternatively, the attacker can leverage unauthenticated access to this script to trigger a reboot via an ifType=reboot action.
- risk 0.58cvss 8.8epss 0.05
/usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute any command via shell metacharacters in the cgi-bin/luci autoUpTime parameter.
- risk 0.51cvss 7.8epss 0.01
Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call.
- risk 0.51cvss 7.8epss 0.01
Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function.
- risk 0.49cvss 7.5epss 0.00
Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.