PT-2023-27640 · Phicomm · Phicomm K2
CVE-2023-40796
·
Publicado
2023-08-25
·
Atualizado
2024-03-07
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Phicomm k2 version 22.6.529.216
Description
The Phicomm k2 router contains a command injection vulnerability via the
luci.sys.call function. This issue allows for remote command execution.Recommendations
For Phicomm k2 version 22.6.529.216, consider disabling the
luci.sys.call function as a temporary workaround until a patch is available. Restrict access to the vulnerable function to minimize the risk of exploitation.Correção
Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Phicomm K2