Перейти к содержимому
Noroxi

Записи phicomm

18 опубликованных записей вендора phicomm.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
1
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

18 записей
  • CVE-2017-11495
    40В плане

    PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; a

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    phicomm · k2\(psg1218\)-firmware20 июл. 2017 г.

  • CVE-2019-19117
    37Наблюдать

    /usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute a

    ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %

    phicomm · k2\(psg1218\) firmware18 нояб. 2019 г.

  • CVE-2022-27373
    36Наблюдать

    Shanghai Feixun Data Communication Technology Co., Ltd router fir302b A2 was discovered to contain a remote command execution (RCE) vulnerab

    ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %

    phicomm · fir303b firmware19 июл. 2022 г.

  • CVE-2022-25219
    33Наблюдать

    A null byte interaction error has been discovered in the code that the telnetd_startup daemon uses to construct a pair of ephemeral password

    ВысокаяCVSS 8,4Эксплойта нетEPSS 1 %

    phicomm · k2 firmware10 мар. 2022 г.

  • CVE-2022-25218
    32Наблюдать

    The use of the RSA algorithm without OAEP, or any other padding scheme, in telnetd_startup, allows an unauthenticated attacker on the local

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    phicomm · k2 firmware10 мар. 2022 г.

  • CVE-2023-40796
    31Наблюдать

    Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    phicomm · k2 firmware25 авг. 2023 г.

  • CVE-2022-48070
    31Наблюдать

    Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade f

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    phicomm · k2 firmware27 янв. 2023 г.

  • CVE-2022-48072
    31Наблюдать

    Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade fun

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    phicomm · k2 firmware27 янв. 2023 г.

  • CVE-2022-25217
    31Наблюдать

    Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network to obtain a root shel

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    phicomm · k2 firmware10 мар. 2022 г.

  • CVE-2022-48073
    30Наблюдать

    Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    phicomm · k2 firmware27 янв. 2023 г.

  • CVE-2022-48071
    30Наблюдать

    Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    phicomm · k2 firmware27 янв. 2023 г.

  • CVE-2022-37780
    29Наблюдать

    Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulnera

    ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %

    phicomm · fir151b firmware7 сент. 2022 г.

  • CVE-2022-37777
    29Наблюдать

    Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers 3.0.1.17 and earlier were discovered to contain a remote command execution (R

    ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %

    phicomm · fir151b firmware7 сент. 2022 г.

  • CVE-2022-37778
    29Наблюдать

    Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulnera

    ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %

    phicomm · fir151b firmware7 сент. 2022 г.

  • CVE-2022-37779
    29Наблюдать

    Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulnera

    ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %

    phicomm · fir151b firmware7 сент. 2022 г.

  • CVE-2022-25214
    29Наблюдать

    Improper access control on the LocalClientList.asp interface allows an unauthenticated remote attacker to obtain sensitive information conce

    ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %

    phicomm · k2 firmware10 мар. 2022 г.

  • CVE-2022-25213
    27Наблюдать

    Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical access to obtain a root

    СредняяCVSS 6,8Эксплойта нетEPSS 0 %

    phicomm · k2 firmware10 мар. 2022 г.

  • CVE-2022-25215
    21Наблюдать

    Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacker to add (or remove) client MAC addresse

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    phicomm · k2 firmware10 мар. 2022 г.