cambiumnetworks CVE Vulnerabilities & Metrics

Focus on cambiumnetworks vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About cambiumnetworks Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with cambiumnetworks. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total cambiumnetworks CVEs: 21
Earliest CVE date: 10 Mar 2017, 10:59 UTC
Latest CVE date: 18 Dec 2023, 18:15 UTC

Latest CVE reference: CVE-2023-6691

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical cambiumnetworks CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.92

Max CVSS: 10.0

Critical CVEs (≥9): 6

CVSS Range vs. Count

Range Count
0.0-3.9 5
4.0-6.9 6
7.0-8.9 4
9.0-10.0 6

CVSS Distribution Chart

Top 5 Highest CVSS cambiumnetworks CVEs

These are the five CVEs with the highest CVSS scores for cambiumnetworks, sorted by severity first and recency.

All CVEs for cambiumnetworks

CVE-2023-6691 cambiumnetworks vulnerability CVSS: 0 18 Dec 2023, 18:15 UTC

Cambium ePMP Force 300-25 version 4.7.0.1 is vulnerable to a code injection vulnerability that could allow an attacker to perform remote code execution and gain root privileges.

CVE-2022-35908 cambiumnetworks vulnerability CVSS: 0 29 Sep 2023, 21:15 UTC

Cambium Enterprise Wi-Fi System Software before 6.4.2 does not sanitize the ping host argument in device-agent.

CVE-2022-1362 cambiumnetworks vulnerability CVSS: 9.3 17 May 2022, 21:15 UTC

The affected On-Premise cnMaestro is vulnerable inside a specific route where a user can upload a crafted package to the system. An attacker could abuse this user-controlled data to execute arbitrary commands on the server.

CVE-2022-1361 cambiumnetworks vulnerability CVSS: 5.0 17 May 2022, 21:15 UTC

The affected On-Premise cnMaestro is vulnerable to a pre-auth data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate data about other user’s accounts and devices.

CVE-2022-1360 cambiumnetworks vulnerability CVSS: 7.5 17 May 2022, 21:15 UTC

The affected On-Premise cnMaestro is vulnerable to execution of code on the cnMaestro hosting server. This could allow a remote attacker to change server configuration settings.

CVE-2022-1359 cambiumnetworks vulnerability CVSS: 5.0 17 May 2022, 21:15 UTC

The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to a restricted directory inside a specific route. If an attacker supplied path traversal charters (../) as part of a filename, the server will save the file where the attacker chooses. This could allow an attacker to write any data to any file in the server.

CVE-2022-1358 cambiumnetworks vulnerability CVSS: 5.0 17 May 2022, 21:15 UTC

The affected On-Premise is vulnerable to data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate and dump all data held in the cnMaestro database.

CVE-2022-1357 cambiumnetworks vulnerability CVSS: 7.5 17 May 2022, 21:15 UTC

The affected On-Premise cnMaestro allows an unauthenticated attacker to access the cnMaestro server and execute arbitrary code in the privileges of the web server. This lack of validation could allow an attacker to append arbitrary data to the logger command.

CVE-2022-1356 cambiumnetworks vulnerability CVSS: 7.2 17 May 2022, 21:15 UTC

cnMaestro is vulnerable to a local privilege escalation. By default, a user does not have root privileges. However, a user can run scripts as sudo, which could allow an attacker to gain root privileges when running user scripts outside allowed commands.

CVE-2020-9022 cambiumnetworks vulnerability CVSS: 4.3 17 Feb 2020, 04:15 UTC

An issue was discovered on Xirrus XR520, XR620, XR2436, and XH2-120 devices. The cgi-bin/ViewPage.cgi user parameter allows XSS.

CVE-2017-5263 cambiumnetworks vulnerability CVSS: 5.4 20 Dec 2017, 22:29 UTC

Versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware lack CSRF controls that can mitigate the effects of CSRF attacks, which are most typically implemented as randomized per-session tokens associated with any web application function, especially destructive ones.

CVE-2017-5262 cambiumnetworks vulnerability CVSS: 7.7 20 Dec 2017, 22:29 UTC

In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access to sensitive information by OID reference.

CVE-2017-5261 cambiumnetworks vulnerability CVSS: 4.0 20 Dec 2017, 22:29 UTC

In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web administrative console expose a file path traversal vulnerability, accessible to all authenticated users.

CVE-2017-5260 cambiumnetworks vulnerability CVSS: 9.0 20 Dec 2017, 22:29 UTC

In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available in the normal web administrative console for the 'user' account, the configuration file is accessible via direct object reference (DRO) at http://<device-ip-or-hostname>/goform/down_cfg_file by this otherwise low privilege 'user' account.

CVE-2017-5259 cambiumnetworks vulnerability CVSS: 9.0 20 Dec 2017, 22:29 UTC

In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or-hostname>/adm/syscmd.asp.

CVE-2017-5258 cambiumnetworks vulnerability CVSS: 3.5 20 Dec 2017, 22:29 UTC

In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows or can guess the RW community string can provide a URL for a configuration file over SNMP with XSS strings in certain SNMP OIDs, serve it via HTTP, and the affected device will perform a configuration restore using the attacker's supplied config file, including the inserted XSS strings.

CVE-2017-5257 cambiumnetworks vulnerability CVSS: 3.5 20 Dec 2017, 22:29 UTC

In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows (or guesses) the SNMP read/write (RW) community string can insert XSS strings in certain SNMP OIDs which will execute in the context of the currently-logged on user.

CVE-2017-5256 cambiumnetworks vulnerability CVSS: 3.5 20 Dec 2017, 22:29 UTC

In version 3.5 and prior of Cambium Networks ePMP firmware, all authenticated users have the ability to update the Device Name and System Description fields in the web administration console, and those fields are vulnerable to persistent cross-site scripting (XSS) injection.

CVE-2017-5255 cambiumnetworks vulnerability CVSS: 9.0 20 Dec 2017, 22:29 UTC

In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows any authenticated user (including the otherwise low-privilege readonly user) to inject shell meta-characters as part of a specially-crafted POST request to the get_chart function and run OS-level commands, effectively as root.

CVE-2017-5254 cambiumnetworks vulnerability CVSS: 9.0 20 Dec 2017, 22:29 UTC

In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passwords for other accounts, including admin, after disabling a client-side protection mechanism.

CVE-2017-5859 cambiumnetworks vulnerability CVSS: 10.0 10 Mar 2017, 10:59 UTC

On Cambium Networks cnPilot R200/201 devices before 4.3, there is a vulnerability involving the certificate of the device and its RSA keys, aka RBN-183.