İçeriğe atla
Noroxi

phicomm kayıtları

phicomm üreticisine ait 18 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

18 kayıt
  • CVE-2017-11495
    40Planlayın

    PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; a

    KritikCVSS 9,8İstismar yokEPSS %3

    phicomm · k2\(psg1218\)-firmware20 Tem 2017

  • CVE-2019-19117
    37İzleyin

    /usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute a

    YüksekCVSS 8,8İstismar yokEPSS %5

    phicomm · k2\(psg1218\) firmware18 Kas 2019

  • CVE-2022-27373
    36İzleyin

    Shanghai Feixun Data Communication Technology Co., Ltd router fir302b A2 was discovered to contain a remote command execution (RCE) vulnerab

    YüksekCVSS 8,8İstismar yokEPSS %4

    phicomm · fir303b firmware19 Tem 2022

  • CVE-2022-25219
    33İzleyin

    A null byte interaction error has been discovered in the code that the telnetd_startup daemon uses to construct a pair of ephemeral password

    YüksekCVSS 8,4İstismar yokEPSS %1

    phicomm · k2 firmware10 Mar 2022

  • CVE-2022-25218
    32İzleyin

    The use of the RSA algorithm without OAEP, or any other padding scheme, in telnetd_startup, allows an unauthenticated attacker on the local

    YüksekCVSS 8,1İstismar yokEPSS %1

    phicomm · k2 firmware10 Mar 2022

  • CVE-2023-40796
    31İzleyin

    Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call.

    YüksekCVSS 7,8İstismar yokEPSS %1

    phicomm · k2 firmware25 Ağu 2023

  • CVE-2022-48070
    31İzleyin

    Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade f

    YüksekCVSS 7,8İstismar yokEPSS %1

    phicomm · k2 firmware27 Oca 2023

  • CVE-2022-48072
    31İzleyin

    Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade fun

    YüksekCVSS 7,8İstismar yokEPSS %1

    phicomm · k2 firmware27 Oca 2023

  • CVE-2022-25217
    31İzleyin

    Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network to obtain a root shel

    YüksekCVSS 7,8İstismar yokEPSS %0

    phicomm · k2 firmware10 Mar 2022

  • CVE-2022-48073
    30İzleyin

    Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext.

    YüksekCVSS 7,5İstismar yokEPSS %0

    phicomm · k2 firmware27 Oca 2023

  • CVE-2022-48071
    30İzleyin

    Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.

    YüksekCVSS 7,5İstismar yokEPSS %0

    phicomm · k2 firmware27 Oca 2023

  • CVE-2022-37780
    29İzleyin

    Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulnera

    YüksekCVSS 7,2İstismar yokEPSS %2

    phicomm · fir151b firmware7 Eyl 2022

  • CVE-2022-37777
    29İzleyin

    Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers 3.0.1.17 and earlier were discovered to contain a remote command execution (R

    YüksekCVSS 7,2İstismar yokEPSS %2

    phicomm · fir151b firmware7 Eyl 2022

  • CVE-2022-37778
    29İzleyin

    Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulnera

    YüksekCVSS 7,2İstismar yokEPSS %2

    phicomm · fir151b firmware7 Eyl 2022

  • CVE-2022-37779
    29İzleyin

    Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulnera

    YüksekCVSS 7,2İstismar yokEPSS %2

    phicomm · fir151b firmware7 Eyl 2022

  • CVE-2022-25214
    29İzleyin

    Improper access control on the LocalClientList.asp interface allows an unauthenticated remote attacker to obtain sensitive information conce

    YüksekCVSS 7,4İstismar yokEPSS %1

    phicomm · k2 firmware10 Mar 2022

  • CVE-2022-25213
    27İzleyin

    Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical access to obtain a root

    OrtaCVSS 6,8İstismar yokEPSS %0

    phicomm · k2 firmware10 Mar 2022

  • CVE-2022-25215
    21İzleyin

    Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacker to add (or remove) client MAC addresse

    OrtaCVSS 5,3İstismar yokEPSS %1

    phicomm · k2 firmware10 Mar 2022