CVE-2017-5259
high · 8.8In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or-hostname>/adm/syscmd.asp.
8.8
CVSS
30.6%
EPSS (exploit prob.)
98th
EPSS percentile
2017-12-20
Published
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-489CWE-319
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| cambiumnetworks | cnpilot_r190v_firmware | <= 4.3.2-r4 |
| cambiumnetworks | cnpilot_r190v | all versions |
| cambiumnetworks | cnpilot_e410_firmware | <= 4.3.2-r4 |
| cambiumnetworks | cnpilot_e410 | all versions |
| cambiumnetworks | cnpilot_r190n_firmware | <= 4.3.2-r4 |
| cambiumnetworks | cnpilot_r190n | all versions |
| cambiumnetworks | cnpilot_e400_firmware | <= 4.3.2-r4 |
| cambiumnetworks | cnpilot_e400 | all versions |
| cambiumnetworks | cnpilot_e600_firmware | <= 4.3.2-r4 |
| cambiumnetworks | cnpilot_e600 | all versions |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-5259