CVE-2023-40796: Phicomm k2 Firmware

High severity, CVSS 7.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call.

Affected products

  • Phicomm k2 Firmware: version 22.6.529.216 only

Published 2023-08-25. Last modified 2026-06-17.