PT-2022-17154 · Phicomm · K2 Firmware+1

·

CVE-2022-25215

·

Published

2022-03-07

·

Updated

2023-08-08

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions No specific software or version information is provided.
Description The issue concerns improper access control on the LocalMACConfig.asp interface. This allows an unauthenticated remote attacker to modify a list of banned hosts by adding or removing client MAC addresses. As a result, clients with the affected MAC addresses are prevented from accessing the WAN or the router.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-25215

Affected Products

K2 Firmware
K3C Firmware