CVE-2022-25215

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/03/2022
Last modified:
08/08/2023

Description

Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacker to add (or remove) client MAC addresses to (or from) a list of banned hosts. Clients with those MAC addresses are then prevented from accessing either the WAN or the router itself.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:phicomm:k2_firmware:*:*:*:*:*:*:*:* 22.5.9.163 (including)
cpe:2.3:h:phicomm:k2:-:*:*:*:*:*:*:*
cpe:2.3:o:phicomm:k3_firmware:*:*:*:*:*:*:*:* 21.5.37.246 (including)
cpe:2.3:h:phicomm:k3:-:*:*:*:*:*:*:*
cpe:2.3:o:phicomm:k3c_firmware:*:*:*:*:*:*:*:* 32.1.15.93 (including)
cpe:2.3:h:phicomm:k3c:-:*:*:*:*:*:*:*
cpe:2.3:o:phicomm:k2g_firmware:*:*:*:*:*:*:*:* 22.6.3.20 (including)
cpe:2.3:h:phicomm:k2g:-:*:*:*:*:*:*:*
cpe:2.3:o:phicomm:k2p_firmware:*:*:*:*:*:*:*:* 20.4.1.7 (including)
cpe:2.3:h:phicomm:k2p:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools