Vulnerability Description
Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phicomm | K2 Firmware | 22.6.3.20 |
| Phicomm | K2 | - |
Related Weaknesses (CWE)
References
- https://befitting-vinca-933.notion.site/Phicomm-K2G-v22-6-3-20-Command-injectionExploitThird Party Advisory
- https://befitting-vinca-933.notion.site/Phicomm-K2G-v22-6-3-20-Command-injectionExploitThird Party Advisory
FAQ
What is CVE-2022-48072?
CVE-2022-48072 is a vulnerability with a CVSS score of 7.8 (HIGH). Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function.
How severe is CVE-2022-48072?
CVE-2022-48072 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-48072?
Check the references section above for vendor advisories and patch information. Affected products include: Phicomm K2 Firmware, Phicomm K2.