Vulnerability Description
PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; alternatively, the attacker can leverage unauthenticated access to this script to trigger a reboot via an ifType=reboot action.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phicomm | K2\(Psg1218\)-Firmware | <= 22.5.11.5 |
| Phicomm | K2\(Psg1218\) | - |
Related Weaknesses (CWE)
References
- https://github.com/ZIllR0/Routers/blob/master/PHICOMMExploitThird Party Advisory
- https://github.com/ZIllR0/Routers/blob/master/PHICOMMExploitThird Party Advisory
FAQ
What is CVE-2017-11495?
CVE-2017-11495 is a vulnerability with a CVSS score of 9.8 (CRITICAL). PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; alternatively, the attacker can leverage unauthenticated acce...
How severe is CVE-2017-11495?
CVE-2017-11495 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-11495?
Check the references section above for vendor advisories and patch information. Affected products include: Phicomm K2\(Psg1218\)-Firmware, Phicomm K2\(Psg1218\).