ID

VAR-201707-0542


CVE

CVE-2017-11495


TITLE

PHICOMM K2 Vulnerability related to input validation on devices

Trust: 0.8

sources: JVNDB: JVNDB-2017-006930

DESCRIPTION

PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; alternatively, the attacker can leverage unauthenticated access to this script to trigger a reboot via an ifType=reboot action. PHICOMM K2(PSG1218) The device contains an input validation vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. PHICOMMK2 (PSG1218) is a wireless router product from China's PHICOMM. An input validation vulnerability exists in PHICOMMK2 (PSG1218) version 22.5.11.5 and earlier

Trust: 2.25

sources: NVD: CVE-2017-11495 // JVNDB: JVNDB-2017-006930 // CNVD: CNVD-2017-37817 // VULHUB: VHN-101923

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-37817

AFFECTED PRODUCTS

vendor:phicommmodel:k2\ -scope:lteversion:22.5.11.5

Trust: 1.0

vendor:phicommmodel:k2scope:lteversion:22.5.11.5

Trust: 0.8

vendor:phicommmodel:k2scope:lteversion:<=22.5.11.5

Trust: 0.6

vendor:phicommmodel:k2\ -scope:eqversion:22.5.11.5

Trust: 0.6

sources: CNVD: CNVD-2017-37817 // JVNDB: JVNDB-2017-006930 // CNNVD: CNNVD-201711-447 // NVD: CVE-2017-11495

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-11495
value: CRITICAL

Trust: 1.0

NVD: CVE-2017-11495
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2017-37817
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201711-447
value: CRITICAL

Trust: 0.6

VULHUB: VHN-101923
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2017-11495
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 8.5
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2017-37817
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 8.5
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-101923
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 8.5
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-11495
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2017-37817 // VULHUB: VHN-101923 // JVNDB: JVNDB-2017-006930 // CNNVD: CNNVD-201711-447 // NVD: CVE-2017-11495

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-101923 // JVNDB: JVNDB-2017-006930 // NVD: CVE-2017-11495

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201711-447

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201711-447

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-006930

PATCH

title:Top Pageurl:http://phicomm.in/

Trust: 0.8

sources: JVNDB: JVNDB-2017-006930

EXTERNAL IDS

db:NVDid:CVE-2017-11495

Trust: 3.1

db:JVNDBid:JVNDB-2017-006930

Trust: 0.8

db:CNNVDid:CNNVD-201711-447

Trust: 0.7

db:CNVDid:CNVD-2017-37817

Trust: 0.6

db:VULHUBid:VHN-101923

Trust: 0.1

sources: CNVD: CNVD-2017-37817 // VULHUB: VHN-101923 // JVNDB: JVNDB-2017-006930 // CNNVD: CNNVD-201711-447 // NVD: CVE-2017-11495

REFERENCES

url:https://github.com/zillr0/routers/blob/master/phicomm

Trust: 3.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-11495

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-11495

Trust: 0.8

sources: CNVD: CNVD-2017-37817 // VULHUB: VHN-101923 // JVNDB: JVNDB-2017-006930 // CNNVD: CNNVD-201711-447 // NVD: CVE-2017-11495

SOURCES

db:CNVDid:CNVD-2017-37817
db:VULHUBid:VHN-101923
db:JVNDBid:JVNDB-2017-006930
db:CNNVDid:CNNVD-201711-447
db:NVDid:CVE-2017-11495

LAST UPDATE DATE

2025-04-20T23:29:40.111000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-37817date:2017-12-21T00:00:00
db:VULHUBid:VHN-101923date:2017-08-15T00:00:00
db:JVNDBid:JVNDB-2017-006930date:2017-09-07T00:00:00
db:CNNVDid:CNNVD-201711-447date:2017-11-21T00:00:00
db:NVDid:CVE-2017-11495date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-37817date:2017-12-21T00:00:00
db:VULHUBid:VHN-101923date:2017-07-20T00:00:00
db:JVNDBid:JVNDB-2017-006930date:2017-09-07T00:00:00
db:CNNVDid:CNNVD-201711-447date:2017-11-21T00:00:00
db:NVDid:CVE-2017-11495date:2017-07-20T22:29:00.187