CVE detail
CVE-2019-19117 — CVE-2019-19117
Published 2019-11-18 · Modified 2026-06-17 · Vendor phicomm · Product k2\(psg1218\)_firmware · Source nvd
HIGH
severity
CVSS-derived band
0.0502
EPSS probability
exploitation probability, 30d
91.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
/usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute any command via shell metacharacters in the cgi-bin/luci autoUpTime parameter.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References