Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cambiumnetworks

First CVE: Mar 10, 2017Active for: 9 yearsTotal CVEs: 23
57.0
VTI Score
TOP TARGET

Cambiumnetworks manufactures a focused line of wireless access points and network management platforms—particularly the CNPilot series and CNMaestro management suite—deployed in enterprise and service-provider networks. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and frequently acquire public exploit tooling. The exposure recurs through classic web-application and command-injection weakness classes: OS command injection, cross-site scripting, path traversal, SQL injection, and improper parameter validation, reflecting the attack surface inherent to internet-facing management interfaces and firmware update mechanisms on network appliances. Defenders should prioritize patching and network isolation for these management platforms, as their role in network administration amplifies the impact of code execution or authentication bypass. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cambiumnetworks over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 10, 2017
9 years ago
Most Recent CVE
Dec 18, 2023
950 days ago

Products(29 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-5255HIGH
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows any authenticated user (including
Dec 20, 20178.884NOYES
CVE-2017-5254HIGH
In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passwords for other accounts, includ
Dec 20, 20178.867NOYES
CVE-2017-5259HIGH
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or
Dec 20, 20178.859NOYES
CVE-2017-5261HIGH
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web administrative console expose a file path traversal vulnerabil
Dec 20, 20178.841NOYES
CVE-2017-5260HIGH
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available in the normal web administrative console
Dec 20, 20178.840NOYES
CVE-2017-7922HIGH
An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community strings are not properly restricted, which may allow an attacker t
Jun 21, 20177.639NOYES
CVE-2017-7918MEDIUM
An Improper Access Control issue was discovered in Cambium Networks ePMP. After a valid user has used SNMP configuration export, an attacker is able to remotely trigger device conf
Jun 21, 20176.835NOYES
CVE-2017-5262HIGH
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access to sensitive information by OID reference.
Dec 20, 20178.031NOYES
CVE-2022-1357CRITICAL
The affected On-Premise cnMaestro allows an unauthenticated attacker to access the cnMaestro server and execute arbitrary code in the privileges of the web server. This lack of val
May 17, 20229.830NONO
CVE-2022-35908HIGH
Cambium Enterprise Wi-Fi System Software before 6.4.2 does not sanitize the ping host argument in device-agent.
Sep 29, 20238.825NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
22%
65%
13%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (13.0%)
Network18 (78.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (8.7%)
Attack Complexity
Low23 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None16 (69.6%)
Unknown0 (0.0%)
Required7 (30.4%)
Privileges Required
Low15 (65.2%)
High0 (0.0%)
None8 (34.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
8 CVEs
34.8% of CVEs· 99th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cambiumnetworks.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cambiumnetworks — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cambiumnetworks's Products

View all 3 CNAs →

Top CWEs