Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2023-6691 Cambium ePMP Force 300-25 version 4.7.0.1 is vulnerable to a code injection vulnerability that could allow an attacker to perform remote code executi… Epmp Force 300 25 Firmware Mitigation only Fix from $1,9502023-12-18 HIGH 8.8 CVE-2022-35908 Cambium Enterprise Wi-Fi System Software before 6.4.2 does not sanitize the ping host argument in device-agent. Enterprise Wi Fi 6.4.2+ Fix from $1,9502023-09-29 CRITICAL 9.8 CVE-2022-1360 The affected On-Premise cnMaestro is vulnerable to execution of code on the cnMaestro hosting server. This could allow a remote attacker to change se… Cnmaestro Mitigation only Fix from $2,3002022-05-17 HIGH 7.5 CVE-2022-1359 The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to a restricted directory inside… Cnmaestro Mitigation only Fix from $1,9502022-05-17 HIGH 7.5 CVE-2022-1361 The affected On-Premise cnMaestro is vulnerable to a pre-auth data exfiltration through improper neutralization of special elements used in an SQL co… Cnmaestro Mitigation only Fix from $1,9502022-05-17 HIGH 7.3 CVE-2022-1362 The affected On-Premise cnMaestro is vulnerable inside a specific route where a user can upload a crafted package to the system. An attacker could ab… Cnmaestro Mitigation only Fix from $1,9502022-05-17 CRITICAL 9.8 CVE-2022-1357 The affected On-Premise cnMaestro allows an unauthenticated attacker to access the cnMaestro server and execute arbitrary code in the privileges of t… Cnmaestro Mitigation only Fix from $2,3002022-05-17 HIGH 7.8 CVE-2022-1356 cnMaestro is vulnerable to a local privilege escalation. By default, a user does not have root privileges. However, a user can run scripts as sudo, w… Cnmaestro Mitigation only Fix from $1,9502022-05-17 HIGH 7.5 CVE-2022-1358 The affected On-Premise is vulnerable to data exfiltration through improper neutralization of special elements used in an SQL command. This could all… Cnmaestro Mitigation only Fix from $1,9502022-05-17 MEDIUM 6.1 CVE-2020-9022 An issue was discovered on Xirrus XR520, XR620, XR2436, and XH2-120 devices. The cgi-bin/ViewPage.cgi user parameter allows XSS. Xh2 120 Firmware No fix yet Fix from $1,6002020-02-17 HIGH 8.8 CVE-2017-5254EPSS 54% In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passw… Epmp 1000 Firmware after 3.5 Fix from $1,9502017-12-20 HIGH 8.8 CVE-2017-5255EPSS 75% In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows an… Epmp 1000 Firmware after 3.5 Fix from $1,9502017-12-20 HIGH 8.8 CVE-2017-5259EPSS 39% In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the … Cnpilot R190v Firmware after 4.3.2-r4 Fix from $1,9502017-12-20 HIGH 8.8 CVE-2017-5260EPSS 8% In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available in the nor… Cnpilot R190v Firmware after 4.3.2-r4 Fix from $1,9502017-12-20 HIGH 8.8 CVE-2017-5261EPSS 9% In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web administrative console expose a… Cnpilot R190v Firmware after 4.3.2-r4 Fix from $1,9502017-12-20 HIGH 8.0 CVE-2017-5262 In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access to sensitive information by … Cnpilot R190v Firmware after 4.3.2-r4 Fix from $1,9502017-12-20 HIGH 8.0 CVE-2017-5263 Versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware lack CSRF controls that can mitigate the effects of CSRF attacks, which are most typ… Cnpilot R190v Firmware after 4.3.2-r4 Fix from $1,9502017-12-20 MEDIUM 5.4 CVE-2017-5256 In version 3.5 and prior of Cambium Networks ePMP firmware, all authenticated users have the ability to update the Device Name and System Description… Epmp 1000 Firmware after 3.5 Fix from $1,6002017-12-20 MEDIUM 5.4 CVE-2017-5257 In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows (or guesses) the SNMP read/write (RW) community string can insert X… Epmp 1000 Firmware after 3.5 Fix from $1,6002017-12-20 MEDIUM 5.4 CVE-2017-5258 In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows or can guess the RW community string can provide a URL for a config… Epmp 1000 Firmware after 3.5 Fix from $1,6002017-12-20 CRITICAL 9.8 CVE-2017-5859 On Cambium Networks cnPilot R200/201 devices before 4.3, there is a vulnerability involving the certificate of the device and its RSA keys, aka RBN-1… Cnpilot R200 Series Firmware after 4.2 Fix from $2,3002017-03-10