CVE-2014-7279: Kankunit Konke Smart Plug Firmware

Critical severity, CVSS 9.8. EPSS: 11.7% chance of exploitation in the next 30 days.

The Konke Smart Plug K does not require authentication for TELNET sessions, which allows remote attackers to obtain "equipment management authority" via TCP traffic to port 23.

Affected products

  • Kankunit Konke Smart Plug Firmware: version k only

Published 2017-03-23. Last modified 2026-06-17.