PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow...
Critical severity
Unreviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Jul 20, 2017
Published to the GitHub Advisory Database
May 17, 2022
Last updated
Jan 27, 2023
PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; alternatively, the attacker can leverage unauthenticated access to this script to trigger a reboot via an ifType=reboot action.
References