← Back

CVE-2022-25214

nvd nist
Published: Mar 10, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.4
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
Exploitability: 2.2 / Impact: 5.2
Source: NVD

Description

Improper access control on the LocalClientList.asp interface allows an unauthenticated remote attacker to obtain sensitive information concerning devices on the local area network, including IP and MAC addresses. Improper access control on the wirelesssetup.asp interface allows an unauthenticated remote attacker to obtain the WPA passphrases for the 2.4GHz and 5.0GHz wireless networks. This is particularly dangerous given that the K2G setup wizard presents the user with the option of using the same password for the 2.4Ghz network and the administrative interface, by clicking a checkbox. When Remote Managment is enabled, these endpoints are exposed to the WAN.

Affected (5)

5 products
K2 Firmware
K3 Firmware
K3c Firmware
K2g Firmware
K2p Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 22.5.9.163
Running on/withPlatform Versions
Phicomm
K2
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 21.5.37.246
Running on/withPlatform Versions
Phicomm
K3
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 32.1.15.93
Running on/withPlatform Versions
Phicomm
K3c
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 22.6.3.20
Running on/withPlatform Versions
Phicomm
K2g
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 20.4.1.7
Running on/withPlatform Versions
Phicomm
K2p
All versions

References (2)

Source: vulnreport@tenable.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.