← Vulnerability feed

Vulnerability record · CVE-2017-5254 · published 20 December 2017

CVE-2017-5254: Cambium ePMP firmware privilege escalation via client-side password change bypass

Cambiumnetworks · Epmp 1000 Firmware

Cambium Networks ePMP firmware version 3.5 and earlier allows non-administrative users 'installer' and 'home' to change passwords for other accounts, including admin, after disabling a client-side protection mechanism. This is an improper access control and privilege management flaw that lets low-privileged users take over higher-privileged accounts.

8.8 CVSS 3.0 High EPSS 54% · top 1.0% CWE-284 · Improper access controlCWE-269 · Improper privilege management
8.8CVSS 3.0 base score, v2 9.0
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passwords for other accounts, including admin, after disabling a client-side protection mechanism.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityThe flaw allows a low-privileged user to gain admin access with no user interaction, and EPSS indicates a high likelihood of exploitation, though no KEV listing or public exploit is confirmed.

What it is

Cambium Networks ePMP firmware version 3.5 and earlier allows non-administrative users 'installer' and 'home' to change passwords for other accounts, including admin, after disabling a client-side protection mechanism. This is an improper access control and privilege management flaw that lets low-privileged users take over higher-privileged accounts.

Impact

An attacker with a low-privileged account can reset the admin password and gain full administrative control of the affected device. This enables complete compromise of the device's configuration and potentially the network it manages.

Attack surface

The vulnerability is network-reachable (AV:N) and requires a low-privileged authenticated account (PR:L), with no user interaction (UI:N). The client-side protection mechanism must be disabled, which an attacker can do since it is client-side.

Exploitation

The CVE is not listed in CISA KEV, but EPSS indicates a high probability of exploitation (0.537, 98.9th percentile). References are third-party advisories and VDB entries, with no public exploit code explicitly mentioned.

What to do

  • Upgrade to a firmware version later than 3.5 as soon as a fixed release is available from Cambium Networks.
  • If immediate upgrade is not possible, restrict network access to the device management interface to trusted hosts only.
  • Remove or disable default 'installer' and 'home' accounts if they are not required, and enforce strong unique passwords for all accounts.
  • Monitor for unauthorized password changes and alert on any admin password reset events.
  • Apply network segmentation to limit the blast radius if a device is compromised.

Detection

  • Monitor authentication logs for password change events, especially those initiated by non-admin accounts.
  • Alert on successful logins to admin accounts from unusual source IPs or after password changes.
  • Audit device configurations for unexpected admin password changes and compare against a known-good baseline.
  • Use network monitoring to detect attempts to access the management interface from untrusted networks.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-5254 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2017-5255Cambium ePMP firmware command injection in get_chart web consoleCambium Networks ePMP firmware version 3.5 and prior fails to sanitize certain parameters on the web management console. Any authenticated user, incl…EPSS 74%analysed5.4CVE-2017-5256Cambiumnetworks epmp 1000 firmware cross-site scripting vulnerabilityIn version 3.5 and prior of Cambium Networks ePMP firmware, all authenticated users have the ability to update the Device Name and System Description…EPSS 0.50%5.4CVE-2017-5257Cambiumnetworks epmp 1000 firmware cross-site scripting vulnerabilityIn version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows (or guesses) the SNMP read/write (RW) community string can insert X…EPSS 0.52%5.4CVE-2017-5258Cambiumnetworks epmp 1000 firmware cross-site scripting vulnerabilityIn version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows or can guess the RW community string can provide a URL for a config…EPSS 0.54%7.8CVE-2026-81963Windows Update Stack link-following privilege escalationWindows Update Stack resolves links improperly before accessing files, a link-following flaw (CWE-59) compounded by improper access control (CWE-284)…KEVEPSS 0.39%analysed10.0CVE-2026-21962Oracle HTTP Server and WebLogic Proxy Plug-in improper access controlOracle HTTP Server and the WebLogic Server Proxy Plug-in (for Apache HTTP Server and IIS) contain an improper access control flaw (CWE-284) in suppor…KEVEPSS 71%analysed10.0CVE-2026-34908Ubiquiti UniFi OS improper access control allows unauthorized system changesUniFi OS devices contain an improper access control flaw (CWE-284) that lets a network-reachable actor make unauthorized changes to the system. The C…KEVEPSS 15%analysed10.0CVE-2026-48907JCE editor for Joomla allows unauthenticated profile creation and PHP uploadThe JCE editor extension for Joomla permits unauthenticated users to create new editor profiles, which leads to upload and execution of PHP code. Thi…KEVEPSS 16%analysed

Source: NIST National Vulnerability Database (record CVE-2017-5254), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.