ZeroHour

CVE-2022-25215

PoC
CVSS 3.1
5.3 medium
EPSS
1%p65
Published
()
Modified
Description

Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacker to add (or remove) client MAC addresses to (or from) a list of banned hosts. Clients with those MAC addresses are then prevented from accessing either the WAN or the router itself.

Vendors
phicomm
Products
k2 firmware, k3 firmware, k3c firmware, k2g firmware, k2p firmware
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.