CVSS v3
7.4
HIGH
EPSS Score
1.2 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
Improper access control on the LocalClientList.asp interface allows an unauthenticated remote attacker to obtain sensitive information concerning devices on the local area network, including IP and MAC addresses. Improper access control on the wirelesssetup.asp interface allows an unauthenticated remote attacker to obtain the WPA passphrases for the 2.4GHz and 5.0GHz wireless networks. This is particularly dangerous given that the K2G setup wizard presents the user with the option of using the same password for the 2.4Ghz network and the administrative interface, by clicking a checkbox. When Remote Managment is enabled, these endpoints are exposed to the WAN.
Technical details
- Published
- 2022-03-10
Frequently asked questions
What is CVE-2022-25214?
Improper access control on the LocalClientList.asp interface allows an unauthenticated remote attacker to obtain sensitive information concerning devices on the local area network, including IP and MAC addresses. Improper access control on the wirelesssetup.asp interface allows an unauthenticated remote attacker to obtain the WPA passphrases for the 2.4GHz and 5.0GHz wireless networks. This is particularly dangerous given that the K2G setup wizard presents the user with the option of using the same password for the 2.4Ghz network and the administrative interface, by clicking a checkbox. When Remote Managment is enabled, these endpoints are exposed to the WAN.
Is CVE-2022-25214 actively exploited?
Active exploitation of CVE-2022-25214 has not been confirmed. The EPSS score is 1.2%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2022-25214?
CVE-2022-25214 has a CVSS v3 base score of 7.4 (HIGH severity).
Is CVE-2022-25214 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2022 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).