CVE Database
/

CVE-2017-5255

Back to search

CVE-2017-5255

Published: Dec 20, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows any authenticated user (including the otherwise low-privilege readonly user) to inject shell meta-characters as part of a specially-crafted POST request to the get_chart function and run OS-level commands, effectively as root.

VendorProductVersions

Cambium Networks

ePMP

affected
3.5 and prior

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now