#VU61204 Improper access control in PHICOMM products - CVE-2022-25218
Published: March 9, 2022
K2
K3
K3C
K2 A7
K2G A1
PHICOMM
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the use of the RSA algorithm without OAEP or any other padding scheme in telnetd_startup. A remote attacker on the local network can manipulate the various iterations of the telnetd startup state machine and eventually obtain a root shell on the device.