Description
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or-hostname>/adm/syscmd.asp.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Subscriptions
Cambiumnetworks
Subscribe
Cnpilot E400
Subscribe
Cnpilot E400 Firmware
Subscribe
Cnpilot E410
Subscribe
Cnpilot E410 Firmware
Subscribe
Cnpilot E600
Subscribe
Cnpilot E600 Firmware
Subscribe
Cnpilot R190n
Subscribe
Cnpilot R190n Firmware
Subscribe
Cnpilot R190v
Subscribe
Cnpilot R190v Firmware
Subscribe
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2024-08-05T14:55:35.778Z
Reserved: 2017-01-09T00:00:00.000Z
Link: CVE-2017-5259
No data.
Status : Modified
Published: 2017-12-20T22:29:00.510
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-5259
No data.
OpenCVE Enrichment
No data.