CVE-2017-5260

In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available in the normal web administrative console for the 'user' account, the configuration file is accessible via direct object reference (DRO) at http://<device-ip-or-hostname>/goform/down_cfg_file by this otherwise low privilege 'user' account.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:cambiumnetworks:cnpilot_r190v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:cambiumnetworks:cnpilot_r190v:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:cambiumnetworks:cnpilot_e410_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:cambiumnetworks:cnpilot_e410:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:cambiumnetworks:cnpilot_r190n_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:cambiumnetworks:cnpilot_r190n:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:cambiumnetworks:cnpilot_e400_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:cambiumnetworks:cnpilot_e400:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:cambiumnetworks:cnpilot_e600_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:cambiumnetworks:cnpilot_e600:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:27

Type Values Removed Values Added
References () https://blog.rapid7.com/2017/12/19/r7-2017-25-cambium-epmp-and-cnpilot-multiple-vulnerabilities/ - Third Party Advisory () https://blog.rapid7.com/2017/12/19/r7-2017-25-cambium-epmp-and-cnpilot-multiple-vulnerabilities/ - Third Party Advisory

Information

Published : 2017-12-20 22:29

Updated : 2024-11-21 03:27


NVD link : CVE-2017-5260

Mitre link : CVE-2017-5260

CVE.ORG link : CVE-2017-5260


JSON object : View

Products Affected

cambiumnetworks

  • cnpilot_r190n
  • cnpilot_r190v_firmware
  • cnpilot_e400_firmware
  • cnpilot_e600_firmware
  • cnpilot_e410
  • cnpilot_r190n_firmware
  • cnpilot_e400
  • cnpilot_r190v
  • cnpilot_e600
  • cnpilot_e410_firmware
CWE
CWE-472

External Control of Assumed-Immutable Web Parameter

CWE-732

Incorrect Permission Assignment for Critical Resource