Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown
CVE-2023-6691
Disclosure Date: December 18, 2023 (last updated December 29, 2023)
Cambium ePMP Force 300-25 version 4.7.0.1 is vulnerable to a code injection vulnerability that could allow an attacker to perform remote code execution and gain root privileges.
0
Attacker Value
Unknown
CVE-2022-35908
Disclosure Date: September 29, 2023 (last updated October 11, 2023)
Cambium Enterprise Wi-Fi System Software before 6.4.2 does not sanitize the ping host argument in device-agent.
0
Attacker Value
Unknown
CVE-2022-1356
Disclosure Date: May 12, 2022 (last updated February 23, 2025)
cnMaestro is vulnerable to a local privilege escalation. By default, a user does not have root privileges. However, a user can run scripts as sudo, which could allow an attacker to gain root privileges when running user scripts outside allowed commands.
0
Attacker Value
Unknown
CVE-2022-1360
Disclosure Date: May 12, 2022 (last updated February 23, 2025)
The affected On-Premise cnMaestro is vulnerable to execution of code on the cnMaestro hosting server. This could allow a remote attacker to change server configuration settings.
0
Attacker Value
Unknown
CVE-2022-1362
Disclosure Date: May 12, 2022 (last updated February 23, 2025)
The affected On-Premise cnMaestro is vulnerable inside a specific route where a user can upload a crafted package to the system. An attacker could abuse this user-controlled data to execute arbitrary commands on the server.
0
Attacker Value
Unknown
CVE-2022-1358
Disclosure Date: May 12, 2022 (last updated February 23, 2025)
The affected On-Premise is vulnerable to data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate and dump all data held in the cnMaestro database.
0
Attacker Value
Unknown
CVE-2022-1359
Disclosure Date: May 12, 2022 (last updated February 23, 2025)
The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to a restricted directory inside a specific route. If an attacker supplied path traversal charters (../) as part of a filename, the server will save the file where the attacker chooses. This could allow an attacker to write any data to any file in the server.
0
Attacker Value
Unknown
CVE-2022-1357
Disclosure Date: May 12, 2022 (last updated February 23, 2025)
The affected On-Premise cnMaestro allows an unauthenticated attacker to access the cnMaestro server and execute arbitrary code in the privileges of the web server. This lack of validation could allow an attacker to append arbitrary data to the logger command.
0
Attacker Value
Unknown
CVE-2022-1361
Disclosure Date: May 12, 2022 (last updated February 23, 2025)
The affected On-Premise cnMaestro is vulnerable to a pre-auth data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate data about other user’s accounts and devices.
0
Attacker Value
Unknown
CVE-2020-9022
Disclosure Date: February 17, 2020 (last updated February 21, 2025)
An issue was discovered on Xirrus XR520, XR620, XR2436, and XH2-120 devices. The cgi-bin/ViewPage.cgi user parameter allows XSS.
0