CVE-2014-7279: Kankunit Konke Smart Plug Firmware
Critical severity, CVSS 9.8. EPSS: 11.7% chance of exploitation in the next 30 days.
The Konke Smart Plug K does not require authentication for TELNET sessions, which allows remote attackers to obtain "equipment management authority" via TCP traffic to port 23.
Affected products
- Kankunit Konke Smart Plug Firmware: version k only
Published 2017-03-23. Last modified 2026-06-17.