Записи phicomm
18 опубликованных записей вендора phicomm.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-312 Cleartext Storage of Sensitive Information2
- CWE-798 Use of Hard-coded Credentials2
- CWE-20 Improper Input Validation1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
18 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2017-11495Эксплойта нет | PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; aphicomm · k2\(psg1218\)-firmware · CWE-20 | Критическая9,8 | — | 3,2 % | 20 июл. 2017 г. |
37Наблюдать | CVE-2019-19117Эксплойта нет | /usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute aphicomm · k2\(psg1218\) firmware · CWE-78 | Высокая8,8 | — | 5,0 % | 18 нояб. 2019 г. |
36Наблюдать | CVE-2022-27373Эксплойта нет | Shanghai Feixun Data Communication Technology Co., Ltd router fir302b A2 was discovered to contain a remote command execution (RCE) vulnerabphicomm · fir303b firmware · CWE-78 | Высокая8,8 | — | 3,6 % | 19 июл. 2022 г. |
33Наблюдать | CVE-2022-25219Эксплойта нет | A null byte interaction error has been discovered in the code that the telnetd_startup daemon uses to construct a pair of ephemeral passwordphicomm · k2 firmware | Высокая8,4 | — | 0,8 % | 10 мар. 2022 г. |
32Наблюдать | CVE-2022-25218Эксплойта нет | The use of the RSA algorithm without OAEP, or any other padding scheme, in telnetd_startup, allows an unauthenticated attacker on the local phicomm · k2 firmware · CWE-327 | Высокая8,1 | — | 1,0 % | 10 мар. 2022 г. |
31Наблюдать | CVE-2023-40796Эксплойта нет | Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call.phicomm · k2 firmware · CWE-77 | Высокая7,8 | — | 0,9 % | 25 авг. 2023 г. |
31Наблюдать | CVE-2022-48070Эксплойта нет | Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade fphicomm · k2 firmware · CWE-78 | Высокая7,8 | — | 0,9 % | 27 янв. 2023 г. |
31Наблюдать | CVE-2022-48072Эксплойта нет | Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade funphicomm · k2 firmware · CWE-78 | Высокая7,8 | — | 0,9 % | 27 янв. 2023 г. |
31Наблюдать | CVE-2022-25217Эксплойта нет | Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network to obtain a root shelphicomm · k2 firmware · CWE-798 | Высокая7,8 | — | 0,3 % | 10 мар. 2022 г. |
30Наблюдать | CVE-2022-48073Эксплойта нет | Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext.phicomm · k2 firmware · CWE-312 | Высокая7,5 | — | 0,5 % | 27 янв. 2023 г. |
30Наблюдать | CVE-2022-48071Эксплойта нет | Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.phicomm · k2 firmware · CWE-312 | Высокая7,5 | — | 0,4 % | 27 янв. 2023 г. |
29Наблюдать | CVE-2022-37780Эксплойта нет | Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulneraphicomm · fir151b firmware | Высокая7,2 | — | 2,2 % | 7 сент. 2022 г. |
29Наблюдать | CVE-2022-37777Эксплойта нет | Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers 3.0.1.17 and earlier were discovered to contain a remote command execution (Rphicomm · fir151b firmware | Высокая7,2 | — | 2,2 % | 7 сент. 2022 г. |
29Наблюдать | CVE-2022-37778Эксплойта нет | Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulneraphicomm · fir151b firmware | Высокая7,2 | — | 2,2 % | 7 сент. 2022 г. |
29Наблюдать | CVE-2022-37779Эксплойта нет | Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulneraphicomm · fir151b firmware | Высокая7,2 | — | 2,2 % | 7 сент. 2022 г. |
29Наблюдать | CVE-2022-25214Эксплойта нет | Improper access control on the LocalClientList.asp interface allows an unauthenticated remote attacker to obtain sensitive information concephicomm · k2 firmware | Высокая7,4 | — | 1,5 % | 10 мар. 2022 г. |
27Наблюдать | CVE-2022-25213Эксплойта нет | Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical access to obtain a root phicomm · k2 firmware · CWE-798 | Средняя6,8 | — | 0,4 % | 10 мар. 2022 г. |
21Наблюдать | CVE-2022-25215Эксплойта нет | Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacker to add (or remove) client MAC addressephicomm · k2 firmware | Средняя5,3 | — | 1,1 % | 10 мар. 2022 г. |
- CVE-2017-1149540В плане
PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; a
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %phicomm · k2\(psg1218\)-firmware20 июл. 2017 г.
- CVE-2019-1911737Наблюдать
/usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute a
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %phicomm · k2\(psg1218\) firmware18 нояб. 2019 г.
- CVE-2022-2737336Наблюдать
Shanghai Feixun Data Communication Technology Co., Ltd router fir302b A2 was discovered to contain a remote command execution (RCE) vulnerab
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %phicomm · fir303b firmware19 июл. 2022 г.
- CVE-2022-2521933Наблюдать
A null byte interaction error has been discovered in the code that the telnetd_startup daemon uses to construct a pair of ephemeral password
ВысокаяCVSS 8,4Эксплойта нетEPSS 1 %phicomm · k2 firmware10 мар. 2022 г.
- CVE-2022-2521832Наблюдать
The use of the RSA algorithm without OAEP, or any other padding scheme, in telnetd_startup, allows an unauthenticated attacker on the local
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %phicomm · k2 firmware10 мар. 2022 г.
- CVE-2023-4079631Наблюдать
Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %phicomm · k2 firmware25 авг. 2023 г.
- CVE-2022-4807031Наблюдать
Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade f
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %phicomm · k2 firmware27 янв. 2023 г.
- CVE-2022-4807231Наблюдать
Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade fun
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %phicomm · k2 firmware27 янв. 2023 г.
- CVE-2022-2521731Наблюдать
Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network to obtain a root shel
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %phicomm · k2 firmware10 мар. 2022 г.
- CVE-2022-4807330Наблюдать
Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %phicomm · k2 firmware27 янв. 2023 г.
- CVE-2022-4807130Наблюдать
Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %phicomm · k2 firmware27 янв. 2023 г.
- CVE-2022-3778029Наблюдать
Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulnera
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %phicomm · fir151b firmware7 сент. 2022 г.
- CVE-2022-3777729Наблюдать
Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers 3.0.1.17 and earlier were discovered to contain a remote command execution (R
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %phicomm · fir151b firmware7 сент. 2022 г.
- CVE-2022-3777829Наблюдать
Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulnera
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %phicomm · fir151b firmware7 сент. 2022 г.
- CVE-2022-3777929Наблюдать
Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulnera
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %phicomm · fir151b firmware7 сент. 2022 г.
- CVE-2022-2521429Наблюдать
Improper access control on the LocalClientList.asp interface allows an unauthenticated remote attacker to obtain sensitive information conce
ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %phicomm · k2 firmware10 мар. 2022 г.
- CVE-2022-2521327Наблюдать
Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical access to obtain a root
СредняяCVSS 6,8Эксплойта нетEPSS 0 %phicomm · k2 firmware10 мар. 2022 г.
- CVE-2022-2521521Наблюдать
Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacker to add (or remove) client MAC addresse
СредняяCVSS 5,3Эксплойта нетEPSS 1 %phicomm · k2 firmware10 мар. 2022 г.