PT-2022-17154 · Phicomm · K2 Firmware+1

Olivia Lucca Fraser

·

Published

2022-03-07

·

Updated

2023-08-08

·

CVE-2022-25215

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions No specific software or version information is provided.
Description The issue concerns improper access control on the LocalMACConfig.asp interface. This allows an unauthenticated remote attacker to modify a list of banned hosts by adding or removing client MAC addresses. As a result, clients with the affected MAC addresses are prevented from accessing the WAN or the router.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2022-25215

Affected Products

K2 Firmware
K3C Firmware