Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

K2 Firmware HIGH 7.8
CVE-2023-40796

Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call.

Mitigation only
Fix from $1,950 2023-08-25
K2 Firmware HIGH 7.8
CVE-2022-48070

Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function.

No fix yet
Fix from $1,950 2023-01-27
K2 Firmware HIGH 7.8
CVE-2022-48072

Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function.

No fix yet
Fix from $1,950 2023-01-27
K2 Firmware HIGH 7.5
CVE-2022-48071

Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.

No fix yet
Fix from $1,950 2023-01-27
K2 Firmware HIGH 7.5
CVE-2022-48073

Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext.

No fix yet
Fix from $1,950 2023-01-27
Fir151b Firmware HIGH 7.2
CVE-2022-37777

Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers 3.0.1.17 and earlier were discovered to contain a remote command execution (RCE) vulne…

Fix: after 3.0.1.17
Fix from $1,950 2022-09-08
Fir151b Firmware HIGH 7.2
CVE-2022-37778

Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulnerability vi…

No fix yet
Fix from $1,950 2022-09-08
Fir151b Firmware HIGH 7.2
CVE-2022-37779

Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulnerability vi…

No fix yet
Fix from $1,950 2022-09-08
Fir151b Firmware HIGH 7.2
CVE-2022-37780

Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulnerability vi…

No fix yet
Fix from $1,950 2022-09-07
Fir303b Firmware HIGH 8.8
CVE-2022-27373

Shanghai Feixun Data Communication Technology Co., Ltd router fir302b A2 was discovered to contain a remote command execution (RCE) vulnerability via…

No fix yet
Fix from $1,950 2022-07-19
K2 Firmware HIGH 8.4
CVE-2022-25219

A null byte interaction error has been discovered in the code that the telnetd_startup daemon uses to construct a pair of ephemeral passwords that al…

Fix: after 32.1.15.93
Fix from $1,950 2022-03-10
K2 Firmware HIGH 8.1
CVE-2022-25218

The use of the RSA algorithm without OAEP, or any other padding scheme, in telnetd_startup, allows an unauthenticated attacker on the local area netw…

Fix: after 32.1.15.93
Fix from $1,950 2022-03-10
K2 Firmware HIGH 7.8
CVE-2022-25217

Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network to obtain a root shell on the …

Fix: after 32.1.15.93
Fix from $1,950 2022-03-10
K2 Firmware HIGH 7.4
CVE-2022-25214

Improper access control on the LocalClientList.asp interface allows an unauthenticated remote attacker to obtain sensitive information concerning dev…

Fix: after 32.1.15.93
Fix from $1,950 2022-03-10
K2 Firmware MEDIUM 5.3
CVE-2022-25215

Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacker to add (or remove) client MAC addresses to (or …

Fix: after 32.1.15.93
Fix from $1,600 2022-03-10
K2 Firmware MEDIUM 6.8
CVE-2022-25213

Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical access to obtain a root shell via…

Fix: after 32.1.15.93
Fix from $1,600 2022-03-10
K2\(psg1218\) Firmware HIGH 8.8
CVE-2019-19117EPSS 5%

/usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute any comman…

No fix yet
Fix from $1,950 2019-11-18
K2\(psg1218\) Firmware CRITICAL 9.8
CVE-2017-11495

PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; alternativ…

Fix: after 22.5.11.5
Fix from $2,300 2017-07-20