← back
CVE-2017-5259observed exploitationCWE-489

CVE-2017-5259

52Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 39%
from disclosure to weapon
Published on NVDDec 20
VulnCheck+2205d
exploitation probability
39%top 2% of all CVEs
observed exploitation
yesVulnCheck
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or-hostname>/adm/syscmd.asp.