← All CVEs

CVE-2017-5259

high · 8.8

In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or-hostname>/adm/syscmd.asp.

8.8
CVSS
30.6%
EPSS (exploit prob.)
98th
EPSS percentile
2017-12-20
Published

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-489CWE-319

Affected products

VendorProductAffected versions
cambiumnetworkscnpilot_r190v_firmware<= 4.3.2-r4
cambiumnetworkscnpilot_r190vall versions
cambiumnetworkscnpilot_e410_firmware<= 4.3.2-r4
cambiumnetworkscnpilot_e410all versions
cambiumnetworkscnpilot_r190n_firmware<= 4.3.2-r4
cambiumnetworkscnpilot_r190nall versions
cambiumnetworkscnpilot_e400_firmware<= 4.3.2-r4
cambiumnetworkscnpilot_e400all versions
cambiumnetworkscnpilot_e600_firmware<= 4.3.2-r4
cambiumnetworkscnpilot_e600all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-5259