Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-25217

25
FAUCET Score

CVE-2022-25217 is a critical vulnerability affecting Phicomm K2 and K3C router firmware versions, where the telnetd_startup service uses a hard-coded cryptographic key pair. This allows a local area network attacker to obtain a root shell via telnet, gaining complete control of the device. The vulnerability has a CVSS score of 7.8 (HIGH) due to its low attack complexity and high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, and no public exploit code or significant community discussion has been identified.

Impacted Technologies

VendorProductVersion(s)CPE
<= 22.5.9.163CPE matchmatch criteria
cpe:2.3:o:phicomm:k2_firmware:*:*:*:*:*:*:*:*
<= 32.1.15.93CPE matchmatch criteria
cpe:2.3:o:phicomm:k3c_firmware:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.32%
Probability of exploitation in next 30 days
EPSS Percentile
24.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0032 is in the 62nd percentile among its peer group of 16,994 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (3)

giteavendor investigatingvia llm_extracted
meterspherevendor investigatingvia llm_extracted
qnapvendor investigatingvia llm_extracted

Vendor Advisories (3)

giteallm-gitea-d78c5b5f1419fb6eHIGH

Unpatchable Vulnerabilities in Phicomm Router Firmware

Feb 1, 2022
qnapllm-qnap-974eed3d5372b0f5HIGH

Unpatchable Vulnerabilities in Phicomm Router Firmware

Feb 1, 2022
meterspherellm-metersphere-339e6ada611378ddHIGH

Unpatchable Vulnerabilities in Phicomm Router Firmware

Feb 1, 2022

References

tenable.com / security/research/tra-2022-01
ExploitThird Party Advisory