CVE-2022-25214 is an improper access control vulnerability affecting Phicomm K2, K2G, K2P, K3, and K3C routers, allowing unauthenticated remote attackers to obtain sensitive local network information and Wi-Fi WPA passphrases. With a CVSS score of 7.4 (High), this vulnerability has a network attack vector and high attack complexity, potentially leading to significant information disclosure. While the vulnerability is not listed in CISA's KEV catalog and has no known public exploits or community discussion, the exposure of these endpoints to the WAN when remote management is enabled increases the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 22.5.9.163CPE matchmatch criteria | cpe:2.3:o:phicomm:k2_firmware:*:*:*:*:*:*:*:* | ||
<= 21.5.37.246CPE matchmatch criteria | cpe:2.3:o:phicomm:k3_firmware:*:*:*:*:*:*:*:* | ||
<= 32.1.15.93CPE matchmatch criteria | cpe:2.3:o:phicomm:k3c_firmware:*:*:*:*:*:*:*:* | ||
<= 22.6.3.20CPE matchmatch criteria | cpe:2.3:o:phicomm:k2g_firmware:*:*:*:*:*:*:*:* | ||
<= 20.4.1.7CPE matchmatch criteria | cpe:2.3:o:phicomm:k2p_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Unpatchable Vulnerabilities in Phicomm Router Firmware
Feb 1, 2022Unpatchable Vulnerabilities in Phicomm Router Firmware
Feb 1, 2022Unpatchable Vulnerabilities in Phicomm Router Firmware
Feb 1, 2022