Improper Neutralization of Null Byte or NUL Character in PHICOMM products - CVE-2022-25219
Published: March 9, 2022
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to a null byte interaction error in the code that the telnetd_startup daemon uses to construct a pair of ephemeral passwords. A remote attacker on the local network can use specially crafted UDP packets and make those ephemeral passwords predictable.
Affected software
K2
K2G A1
K2 A7
K3C