phicomm kayıtları
phicomm üreticisine ait 18 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-312 Cleartext Storage of Sensitive Information2
- CWE-798 Use of Hard-coded Credentials2
- CWE-20 Improper Input Validation1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
18 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2017-11495İstismar yok | PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; aphicomm · k2\(psg1218\)-firmware · CWE-20 | Kritik9,8 | — | %3,2 | 20 Tem 2017 |
37İzleyin | CVE-2019-19117İstismar yok | /usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute aphicomm · k2\(psg1218\) firmware · CWE-78 | Yüksek8,8 | — | %5,0 | 18 Kas 2019 |
36İzleyin | CVE-2022-27373İstismar yok | Shanghai Feixun Data Communication Technology Co., Ltd router fir302b A2 was discovered to contain a remote command execution (RCE) vulnerabphicomm · fir303b firmware · CWE-78 | Yüksek8,8 | — | %3,6 | 19 Tem 2022 |
33İzleyin | CVE-2022-25219İstismar yok | A null byte interaction error has been discovered in the code that the telnetd_startup daemon uses to construct a pair of ephemeral passwordphicomm · k2 firmware | Yüksek8,4 | — | %0,8 | 10 Mar 2022 |
32İzleyin | CVE-2022-25218İstismar yok | The use of the RSA algorithm without OAEP, or any other padding scheme, in telnetd_startup, allows an unauthenticated attacker on the local phicomm · k2 firmware · CWE-327 | Yüksek8,1 | — | %1,0 | 10 Mar 2022 |
31İzleyin | CVE-2023-40796İstismar yok | Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call.phicomm · k2 firmware · CWE-77 | Yüksek7,8 | — | %0,9 | 25 Ağu 2023 |
31İzleyin | CVE-2022-48070İstismar yok | Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade fphicomm · k2 firmware · CWE-78 | Yüksek7,8 | — | %0,9 | 27 Oca 2023 |
31İzleyin | CVE-2022-48072İstismar yok | Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade funphicomm · k2 firmware · CWE-78 | Yüksek7,8 | — | %0,9 | 27 Oca 2023 |
31İzleyin | CVE-2022-25217İstismar yok | Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network to obtain a root shelphicomm · k2 firmware · CWE-798 | Yüksek7,8 | — | %0,3 | 10 Mar 2022 |
30İzleyin | CVE-2022-48073İstismar yok | Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext.phicomm · k2 firmware · CWE-312 | Yüksek7,5 | — | %0,5 | 27 Oca 2023 |
30İzleyin | CVE-2022-48071İstismar yok | Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.phicomm · k2 firmware · CWE-312 | Yüksek7,5 | — | %0,4 | 27 Oca 2023 |
29İzleyin | CVE-2022-37780İstismar yok | Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulneraphicomm · fir151b firmware | Yüksek7,2 | — | %2,2 | 7 Eyl 2022 |
29İzleyin | CVE-2022-37777İstismar yok | Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers 3.0.1.17 and earlier were discovered to contain a remote command execution (Rphicomm · fir151b firmware | Yüksek7,2 | — | %2,2 | 7 Eyl 2022 |
29İzleyin | CVE-2022-37778İstismar yok | Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulneraphicomm · fir151b firmware | Yüksek7,2 | — | %2,2 | 7 Eyl 2022 |
29İzleyin | CVE-2022-37779İstismar yok | Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulneraphicomm · fir151b firmware | Yüksek7,2 | — | %2,2 | 7 Eyl 2022 |
29İzleyin | CVE-2022-25214İstismar yok | Improper access control on the LocalClientList.asp interface allows an unauthenticated remote attacker to obtain sensitive information concephicomm · k2 firmware | Yüksek7,4 | — | %1,5 | 10 Mar 2022 |
27İzleyin | CVE-2022-25213İstismar yok | Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical access to obtain a root phicomm · k2 firmware · CWE-798 | Orta6,8 | — | %0,4 | 10 Mar 2022 |
21İzleyin | CVE-2022-25215İstismar yok | Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacker to add (or remove) client MAC addressephicomm · k2 firmware | Orta5,3 | — | %1,1 | 10 Mar 2022 |
- CVE-2017-1149540Planlayın
PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; a
KritikCVSS 9,8İstismar yokEPSS %3phicomm · k2\(psg1218\)-firmware20 Tem 2017
- CVE-2019-1911737İzleyin
/usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute a
YüksekCVSS 8,8İstismar yokEPSS %5phicomm · k2\(psg1218\) firmware18 Kas 2019
- CVE-2022-2737336İzleyin
Shanghai Feixun Data Communication Technology Co., Ltd router fir302b A2 was discovered to contain a remote command execution (RCE) vulnerab
YüksekCVSS 8,8İstismar yokEPSS %4phicomm · fir303b firmware19 Tem 2022
- CVE-2022-2521933İzleyin
A null byte interaction error has been discovered in the code that the telnetd_startup daemon uses to construct a pair of ephemeral password
YüksekCVSS 8,4İstismar yokEPSS %1phicomm · k2 firmware10 Mar 2022
- CVE-2022-2521832İzleyin
The use of the RSA algorithm without OAEP, or any other padding scheme, in telnetd_startup, allows an unauthenticated attacker on the local
YüksekCVSS 8,1İstismar yokEPSS %1phicomm · k2 firmware10 Mar 2022
- CVE-2023-4079631İzleyin
Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call.
YüksekCVSS 7,8İstismar yokEPSS %1phicomm · k2 firmware25 Ağu 2023
- CVE-2022-4807031İzleyin
Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade f
YüksekCVSS 7,8İstismar yokEPSS %1phicomm · k2 firmware27 Oca 2023
- CVE-2022-4807231İzleyin
Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade fun
YüksekCVSS 7,8İstismar yokEPSS %1phicomm · k2 firmware27 Oca 2023
- CVE-2022-2521731İzleyin
Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network to obtain a root shel
YüksekCVSS 7,8İstismar yokEPSS %0phicomm · k2 firmware10 Mar 2022
- CVE-2022-4807330İzleyin
Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext.
YüksekCVSS 7,5İstismar yokEPSS %0phicomm · k2 firmware27 Oca 2023
- CVE-2022-4807130İzleyin
Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.
YüksekCVSS 7,5İstismar yokEPSS %0phicomm · k2 firmware27 Oca 2023
- CVE-2022-3778029İzleyin
Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulnera
YüksekCVSS 7,2İstismar yokEPSS %2phicomm · fir151b firmware7 Eyl 2022
- CVE-2022-3777729İzleyin
Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers 3.0.1.17 and earlier were discovered to contain a remote command execution (R
YüksekCVSS 7,2İstismar yokEPSS %2phicomm · fir151b firmware7 Eyl 2022
- CVE-2022-3777829İzleyin
Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulnera
YüksekCVSS 7,2İstismar yokEPSS %2phicomm · fir151b firmware7 Eyl 2022
- CVE-2022-3777929İzleyin
Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulnera
YüksekCVSS 7,2İstismar yokEPSS %2phicomm · fir151b firmware7 Eyl 2022
- CVE-2022-2521429İzleyin
Improper access control on the LocalClientList.asp interface allows an unauthenticated remote attacker to obtain sensitive information conce
YüksekCVSS 7,4İstismar yokEPSS %1phicomm · k2 firmware10 Mar 2022
- CVE-2022-2521327İzleyin
Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical access to obtain a root
OrtaCVSS 6,8İstismar yokEPSS %0phicomm · k2 firmware10 Mar 2022
- CVE-2022-2521521İzleyin
Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacker to add (or remove) client MAC addresse
OrtaCVSS 5,3İstismar yokEPSS %1phicomm · k2 firmware10 Mar 2022