PT-2017-16427 · Cambium Networks · Cnpilot

Karn Ganeshen

·

Published

2017-12-20

·

Updated

2025-09-15

·

CVE-2017-5259

CVSS v2.0
9.0
VectorAV:N/AC:L/Au:S/C:C/I:C/A:C

Name of the Vulnerable Software and Affected Versions:

Cambium Networks cnPilot firmware versions 4.3.2-R4 and prior

Description:

The issue concerns an undocumented, root-privilege administration web shell accessible via a specific HTTP path. This path is "https://<device-ip-or-hostname>/adm/syscmd.asp".

Recommendations:

For versions 4.3.2-R4 and prior, consider restricting access to the "/adm/syscmd.asp" endpoint until a patch is available. As a temporary workaround, limit exposure by disabling remote access to the administration interface if possible. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2017-5259

Affected Products

Cnpilot