In version 3.5 and prior of Cambium Networks ePMP firmware,...
Vulnerability Description
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows any authenticated user (including the otherwise low-privilege readonly user) to inject shell meta-characters as part of a specially-crafted POST request to the get_chart function and run OS-level commands, effectively as root.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-5255
Credits & Attribution
No credits recorded in the NVD database.
References
More from Cambium Networks
View All →Affected Vendor
Cambium Networks
View all reports →