CVE-2022-25217
Last modified
CVE-2022-25217 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network to obtain a root shell on the device over telnet. The builds of telnetd_startup included in the version 22.5.9.163 of the K2 firmware, and version 32.1.15.93 of the K3C firmware (possibly amongst many other releases) included both the private and public RSA keys. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network to obtain a root shell on the device over telnet. The builds of telnetd_startup included in the version 22.5.9.163 of the K2 firmware, and version 32.1.15.93 of the K3C firmware (possibly amongst many other releases) included both the private and public RSA keys. The remaining versions cited here redacted the private key, but left the public key unchanged. An attacker in possession of the leaked private key may, through a scripted exchange of UDP packets, instruct telnetd_startup to spawn an unauthenticated telnet shell as root, by means of which they can then obtain complete control of the device. A consequence of the limited availablility of firmware images for testing is that models and versions not listed here may share this vulnerability.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Phicomm | K2 Firmware | <= 22.5.9.163 |
| Phicomm | K3c Firmware | <= 32.1.15.93 |
References
- https://www.tenable.com/security/research/tra-2022-01Exploit, Third Party Advisory
- https://www.tenable.com/security/research/tra-2022-01Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-25217?
How severe is CVE-2022-25217?
How do I fix CVE-2022-25217?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-25211A missing permission check in Jenkins SWAMP Plugin 1.2.6 and…8.8
- CVE-2022-25212A cross-site request forgery (CSRF) vulnerability in Jenkins…8.8
- CVE-2022-25213Improper physical access control and use of hard-coded crede…6.8
- CVE-2022-25214Improper access control on the LocalClientList.asp interface…7.4
- CVE-2022-25215Improper access control on the LocalMACConfig.asp interface …5.3
- CVE-2022-25216An absolute path traversal vulnerability allows a remote att…7.5
- CVE-2022-25218The use of the RSA algorithm without OAEP, or any other padd…8.1
- CVE-2022-25219A null byte interaction error has been discovered in the cod…8.4
- CVE-2022-2522Heap-based Buffer Overflow in GitHub repository vim/vim prio…7.8
- CVE-2022-25220PeteReport Version 0.5 allows an authenticated admin user to…4.8
- CVE-2022-25221Money Transfer Management System Version 1.0 allows an attac…6.1
- CVE-2022-25222Money Transfer Management System Version 1.0 allows an unaut…9.8
Are you affected by CVE-2022-25217?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
