#VU61206 Improper Neutralization of Null Byte or NUL Character in PHICOMM products - CVE-2022-25219
Published: March 9, 2022
K2
K3
K3C
K2 A7
K2G A1
PHICOMM
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to a null byte interaction error in the code that the telnetd_startup daemon uses to construct a pair of ephemeral passwords. A remote attacker on the local network can use specially crafted UDP packets and make those ephemeral passwords predictable.