VulnerabilityModified
CVE-2022-37778
Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulnerability via the current_time parameter of the time function.
HIGH 7.2EPSS 2.17%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulnerability via the current_time parameter of the time function.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.17% probability · 81th percentile
- CISA KEV
- Not listed
- Affected
- phicomm/fir151b firmware · phicomm/fir302e firmware · phicomm/fir300b firmware · phicomm/fir303b firmware
- Source
- cve@mitre.org
References
- https://github.com/SLoSnow9879/Phicomm_Router/blob/main/Time.mdExploit, Third Party Advisory
- https://github.com/SLoSnow9879/Phicomm_Router/blob/main/Time.mdExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.