Vulnerabilities > Cambiumnetworks > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-05-17 CVE-2022-1362 OS Command Injection vulnerability in Cambiumnetworks Cnmaestro 2.4.2/3.0.0/3.0.3
The affected On-Premise cnMaestro is vulnerable inside a specific route where a user can upload a crafted package to the system.
network
cambiumnetworks CWE-78
critical
9.3
2017-12-20 CVE-2017-5260 Incorrect Permission Assignment for Critical Resource vulnerability in Cambiumnetworks products
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available in the normal web administrative console for the 'user' account, the configuration file is accessible via direct object reference (DRO) at http://<device-ip-or-hostname>/goform/down_cfg_file by this otherwise low privilege 'user' account.
network
low complexity
cambiumnetworks CWE-732
critical
9.0
2017-12-20 CVE-2017-5259 Cleartext Transmission of Sensitive Information vulnerability in Cambiumnetworks products
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or-hostname>/adm/syscmd.asp.
network
low complexity
cambiumnetworks CWE-319
critical
9.0
2017-12-20 CVE-2017-5255 OS Command Injection vulnerability in Cambiumnetworks Epmp 1000 Firmware and Epmp 2000 Firmware
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows any authenticated user (including the otherwise low-privilege readonly user) to inject shell meta-characters as part of a specially-crafted POST request to the get_chart function and run OS-level commands, effectively as root.
network
low complexity
cambiumnetworks CWE-78
critical
9.0
2017-12-20 CVE-2017-5254 Improper Privilege Management vulnerability in Cambiumnetworks Epmp 1000 Firmware and Epmp 2000 Firmware
In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passwords for other accounts, including admin, after disabling a client-side protection mechanism.
network
low complexity
cambiumnetworks CWE-269
critical
9.0
2017-03-10 CVE-2017-5859 Unspecified vulnerability in Cambiumnetworks Cnpilot R200 Series Firmware
On Cambium Networks cnPilot R200/201 devices before 4.3, there is a vulnerability involving the certificate of the device and its RSA keys, aka RBN-183.
network
low complexity
cambiumnetworks
critical
10.0