Cambium Networks cnMaestro Path Traversal
Vulnerability Description
The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to a restricted directory inside a specific route. If an attacker supplied path traversal charters (../) as part of a filename, the server will save the file where the attacker chooses. This could allow an attacker to write any data to any file in the server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-1359
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Noam Moshe of Claroty reported these vulnerabilities to CISA.
More from Cambium Networks
View All →Affected Vendor
Cambium Networks
View all reports →