Cambiumnetworks manufactures a focused line of wireless access points and network management platforms—particularly the CNPilot series and CNMaestro management suite—deployed in enterprise and service-provider networks. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and frequently acquire public exploit tooling. The exposure recurs through classic web-application and command-injection weakness classes: OS command injection, cross-site scripting, path traversal, SQL injection, and improper parameter validation, reflecting the attack surface inherent to internet-facing management interfaces and firmware update mechanisms on network appliances. Defenders should prioritize patching and network isolation for these management platforms, as their role in network administration amplifies the impact of code execution or authentication bypass. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cambiumnetworks over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5255HIGH In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows any authenticated user (including | Dec 20, 2017 | 8.8 | 84 | NO | YES |
CVE-2017-5254HIGH In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passwords for other accounts, includ | Dec 20, 2017 | 8.8 | 67 | NO | YES |
CVE-2017-5259HIGH In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or | Dec 20, 2017 | 8.8 | 59 | NO | YES |
CVE-2017-5261HIGH In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web administrative console expose a file path traversal vulnerabil | Dec 20, 2017 | 8.8 | 41 | NO | YES |
CVE-2017-5260HIGH In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available in the normal web administrative console | Dec 20, 2017 | 8.8 | 40 | NO | YES |
CVE-2017-7922HIGH An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community strings are not properly restricted, which may allow an attacker t | Jun 21, 2017 | 7.6 | 39 | NO | YES |
CVE-2017-7918MEDIUM An Improper Access Control issue was discovered in Cambium Networks ePMP. After a valid user has used SNMP configuration export, an attacker is able to remotely trigger device conf | Jun 21, 2017 | 6.8 | 35 | NO | YES |
CVE-2017-5262HIGH In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access to sensitive information by OID reference. | Dec 20, 2017 | 8.0 | 31 | NO | YES |
CVE-2022-1357CRITICAL The affected On-Premise cnMaestro allows an unauthenticated attacker to access the cnMaestro server and execute arbitrary code in the privileges of the web server. This lack of val | May 17, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-35908HIGH Cambium Enterprise Wi-Fi System Software before 6.4.2 does not sanitize the ping host argument in device-agent. | Sep 29, 2023 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cambiumnetworks.
Media articles that mention a CVE ID that affects a product developed by Cambiumnetworks — matched by CVE ID, not by vendor name.