CVE-2022-25217 is a critical vulnerability affecting Phicomm K2 and K3C router firmware versions, where the telnetd_startup service uses a hard-coded cryptographic key pair. This allows a local area network attacker to obtain a root shell via telnet, gaining complete control of the device. The vulnerability has a CVSS score of 7.8 (HIGH) due to its low attack complexity and high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, and no public exploit code or significant community discussion has been identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 22.5.9.163CPE matchmatch criteria | cpe:2.3:o:phicomm:k2_firmware:*:*:*:*:*:*:*:* | ||
<= 32.1.15.93CPE matchmatch criteria | cpe:2.3:o:phicomm:k3c_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Unpatchable Vulnerabilities in Phicomm Router Firmware
Feb 1, 2022Unpatchable Vulnerabilities in Phicomm Router Firmware
Feb 1, 2022Unpatchable Vulnerabilities in Phicomm Router Firmware
Feb 1, 2022