CVE-2017-5260 describes a Direct Object Reference (DOR) vulnerability in Cambium Networks cnPilot firmware versions 4.3.2-R4 and prior, affecting multiple cnPilot E-series and R-series devices. A low-privileged 'user' account can directly access the device's configuration file via a specific URL, even though the option is not available in the web interface. This vulnerability has a CVSSv3 score of 8.8 (High), indicating a critical risk due to its network-based attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability impacts. While not listed on the KEV catalog, a Metasploit module exists for exploitation, and it has garnered some community discussion and media coverage, suggesting awareness among threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.3.2-r4CPE matchmatch criteria | cpe:2.3:o:cambiumnetworks:cnpilot_r190v_firmware:*:*:*:*:*:*:*:* | ||
<= 4.3.2-r4CPE matchmatch criteria | cpe:2.3:o:cambiumnetworks:cnpilot_e410_firmware:*:*:*:*:*:*:*:* | ||
<= 4.3.2-r4CPE matchmatch criteria | cpe:2.3:o:cambiumnetworks:cnpilot_r190n_firmware:*:*:*:*:*:*:*:* | ||
<= 4.3.2-r4CPE matchmatch criteria | cpe:2.3:o:cambiumnetworks:cnpilot_e400_firmware:*:*:*:*:*:*:*:* | ||
<= 4.3.2-r4CPE matchmatch criteria | cpe:2.3:o:cambiumnetworks:cnpilot_e600_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.