Vulnerability record · CVE-2017-5254 · published 20 December 2017
CVE-2017-5254: Cambium ePMP firmware privilege escalation via client-side password change bypass
Cambiumnetworks · Epmp 1000 Firmware
Cambium Networks ePMP firmware version 3.5 and earlier allows non-administrative users 'installer' and 'home' to change passwords for other accounts, including admin, after disabling a client-side protection mechanism. This is an improper access control and privilege management flaw that lets low-privileged users take over higher-privileged accounts.
Description
In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passwords for other accounts, including admin, after disabling a client-side protection mechanism.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows a low-privileged user to gain admin access with no user interaction, and EPSS indicates a high likelihood of exploitation, though no KEV listing or public exploit is confirmed.
What it is
Cambium Networks ePMP firmware version 3.5 and earlier allows non-administrative users 'installer' and 'home' to change passwords for other accounts, including admin, after disabling a client-side protection mechanism. This is an improper access control and privilege management flaw that lets low-privileged users take over higher-privileged accounts.
Impact
An attacker with a low-privileged account can reset the admin password and gain full administrative control of the affected device. This enables complete compromise of the device's configuration and potentially the network it manages.
Attack surface
The vulnerability is network-reachable (AV:N) and requires a low-privileged authenticated account (PR:L), with no user interaction (UI:N). The client-side protection mechanism must be disabled, which an attacker can do since it is client-side.
Exploitation
The CVE is not listed in CISA KEV, but EPSS indicates a high probability of exploitation (0.537, 98.9th percentile). References are third-party advisories and VDB entries, with no public exploit code explicitly mentioned.
What to do
- Upgrade to a firmware version later than 3.5 as soon as a fixed release is available from Cambium Networks.
- If immediate upgrade is not possible, restrict network access to the device management interface to trusted hosts only.
- Remove or disable default 'installer' and 'home' accounts if they are not required, and enforce strong unique passwords for all accounts.
- Monitor for unauthorized password changes and alert on any admin password reset events.
- Apply network segmentation to limit the blast radius if a device is compromised.
Detection
- Monitor authentication logs for password change events, especially those initiated by non-admin accounts.
- Alert on successful logins to admin accounts from unusual source IPs or after password changes.
- Audit device configurations for unexpected admin password changes and compare against a known-good baseline.
- Use network monitoring to detect attempts to access the management interface from untrusted networks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://blog.rapid7.com/2017/12/19/r7-2017-25-cambium-epmp-and-cnpilot-multiple-vulnerabilities/ | Third Party AdvisoryVDB Entry |
| https://blog.rapid7.com/2017/12/19/r7-2017-25-cambium-epmp-and-cnpilot-multiple-vulnerabilities/ | Third Party AdvisoryVDB Entry |
Track CVE-2017-5254 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-5254), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.