Phicomm's vulnerability portfolio centers on consumer and small-business networking devices, particularly its K2 and K3C router lines and related firmware, which occupy a prominent niche in residential and branch-office deployments. Its disclosures cluster around firmware-level weaknesses including OS command injection, hard-coded credentials, and cleartext storage of sensitive information—issues endemic to embedded device codebases where security was historically secondary to rapid iteration. A meaningful share of these vulnerabilities reach serious severity, reflecting the direct access and privilege-escalation potential inherent to unauthenticated command-injection flaws on internet-facing appliances. Defenders should inventory affected Phicomm devices and treat firmware updates as a priority given the device's persistence in long-lived network deployments; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phicomm over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27373HIGH Shanghai Feixun Data Communication Technology Co., Ltd router fir302b A2 was discovered to contain a remote command execution (RCE) vulnerability via the Ping function. | Jul 19, 2022 | 8.8 | 29 | NO | NO |
CVE-2019-19117HIGH /usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute any command via shell metacharacters in t | Nov 18, 2019 | 8.8 | 29 | NO | NO |
CVE-2017-11495CRITICAL PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; alternatively, the attacker can leverage | Jul 20, 2017 | 9.8 | 29 | NO | NO |
CVE-2022-25219HIGH A null byte interaction error has been discovered in the code that the telnetd_startup daemon uses to construct a pair of ephemeral passwords that allow a user to spawn a telnet se | Mar 10, 2022 | 8.4 | 26 | NO | NO |
CVE-2022-48072HIGH Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function. | Jan 27, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-48070HIGH Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function. | Jan 27, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-37778HIGH Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulnerability via the current_time parameter of | Sep 8, 2022 | 7.2 | 25 | NO | NO |
CVE-2022-25217HIGH Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network to obtain a root shell on the device over telnet. The builds | Mar 10, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-48073HIGH Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext. | Jan 27, 2023 | 7.5 | 24 | NO | NO |
CVE-2022-48071HIGH Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext. | Jan 27, 2023 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phicomm.
Media articles that mention a CVE ID that affects a product developed by Phicomm — matched by CVE ID, not by vendor name.