CVE-2022-25215
10.03.2022, 17:47
Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacker to add (or remove) client MAC addresses to (or from) a list of banned hosts. Clients with those MAC addresses are then prevented from accessing either the WAN or the router itself.Enginsight
Vendor | Product | Version |
---|---|---|
phicomm | k2_firmware | 𝑥 ≤ 22.5.9.163 |
phicomm | k3_firmware | 𝑥 ≤ 21.5.37.246 |
phicomm | k3c_firmware | 𝑥 ≤ 32.1.15.93 |
phicomm | k2g_firmware | 𝑥 ≤ 22.6.3.20 |
phicomm | k2p_firmware | 𝑥 ≤ 20.4.1.7 |
𝑥
= Vulnerable software versions