CVE Database
/

CVE-2017-5256

Back to search

CVE-2017-5256

Published: Dec 20, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

In version 3.5 and prior of Cambium Networks ePMP firmware, all authenticated users have the ability to update the Device Name and System Description fields in the web administration console, and those fields are vulnerable to persistent cross-site scripting (XSS) injection.

VendorProductVersions

Cambium Networks

ePMP

affected
3.5 and prior

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now