Phicomm
phicomm
18 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (18)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call. |
Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext. |
Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function. |
Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext. |
Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function. |
1Phicomm 4Fir151b Firmware Fir300b FirmwareFir302e Firmware+1 moreNov 21, 2024 Sep 8, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulnerability via the sendnum parameter of the ping function. |
1Phicomm 4Fir151b Firmware Fir300b FirmwareFir302e Firmware+1 moreNov 21, 2024 Sep 8, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulnerability via the current_time parameter of the time function. |
1Phicomm 4Fir151b Firmware Fir300b FirmwareFir302e Firmware+1 moreNov 21, 2024 Sep 8, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers 3.0.1.17 and earlier were discovered to contain a remote command execution (RCE) vulnerability via the trHops parameter of the tracert function. |
1Phicomm 4Fir151b Firmware Fir300b FirmwareFir302e Firmware+1 moreJun 17, 2025 Sep 7, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulnerability via the pingAddr parameter of the tracert function. |
Shanghai Feixun Data Communication Technology Co., Ltd router fir302b A2 was discovered to contain a remote command execution (RCE) vulnerability via the Ping function. |
1Phicomm 5K2 Firmware K2g FirmwareK2p Firmware+2 moreNov 21, 2024 Mar 10, 2022 N/A· v4 8.4 HIGH· v3 6.9 MEDIUM· v2 A null byte interaction error has been discovered in the code that the telnetd_startup daemon uses to construct a pair of ephemeral passwords that allow a user to spawn a telnet service on the router, and to ensure that...Show more |
1Phicomm 5K2 Firmware K2g FirmwareK2p Firmware+2 moreNov 21, 2024 Mar 10, 2022 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 The use of the RSA algorithm without OAEP, or any other padding scheme, in telnetd_startup, allows an unauthenticated attacker on the local area network to achieve a significant degree of control over the "plaintext" to...Show more |
1Phicomm 2K2 Firmware K3c FirmwareNov 21, 2024 Mar 10, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network to obtain a root shell on the device over telnet. The builds of telnetd_startup included in the versi...Show more |
1Phicomm 5K2 Firmware K2g FirmwareK2p Firmware+2 moreNov 21, 2024 Mar 10, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacker to add (or remove) client MAC addresses to (or from) a list of banned hosts. Clients with those MAC addresses are then...Show more |
1Phicomm 5K2 Firmware K2g FirmwareK2p Firmware+2 moreNov 21, 2024 Mar 10, 2022 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Improper access control on the LocalClientList.asp interface allows an unauthenticated remote attacker to obtain sensitive information concerning devices on the local area network, including IP and MAC addresses. Imprope...Show more |
1Phicomm 5K2 Firmware K2g FirmwareK2p Firmware+2 moreNov 21, 2024 Mar 10, 2022 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical access to obtain a root shell via an unprotected UART port on the device. The same port exposes an unaut...Show more |
/usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute any command via shell metacharacters in the cgi-bin/luci autoUpTime parameter. |
1Phicomm 1K2(psg1218) Firmware May 13, 2026 Jul 20, 2017 N/A· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; alternatively, the attacker can leverage unauthenticated access to this script to...Show more |