Vulnerability record · CVE-2017-5255 · published 20 December 2017
CVE-2017-5255: Cambium ePMP firmware command injection in get_chart web console
Cambiumnetworks · Epmp 1000 Firmware
Cambium Networks ePMP firmware version 3.5 and prior fails to sanitize certain parameters on the web management console. Any authenticated user, including the low-privilege readonly account, can inject shell meta-characters via a crafted POST to the get_chart function and execute OS commands as root.
Description
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows any authenticated user (including the otherwise low-privilege readonly user) to inject shell meta-characters as part of a specially-crafted POST request to the get_chart function and run OS-level commands, effectively as root.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityNetwork-reachable root command injection with a low-privilege authentication requirement and public exploit code, though not observed in KEV or ransomware campaigns.
What it is
Cambium Networks ePMP firmware version 3.5 and prior fails to sanitize certain parameters on the web management console. Any authenticated user, including the low-privilege readonly account, can inject shell meta-characters via a crafted POST to the get_chart function and execute OS commands as root.
Impact
An attacker with any valid account gains root-level command execution on the affected access point, allowing full device compromise, configuration changes, and use as a network foothold.
Attack surface
Reachable over the network through the web management console; the attacker must be authenticated but needs no user interaction, and even the lowest-privilege readonly role suffices.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.74556, ~99.5th percentile) and public exploit code exists via Exploit-DB, indicating active interest and easy weaponization.
What to do
- Upgrade ePMP firmware beyond version 3.5 to a vendor-supported release.
- Restrict web management console access to a trusted management VLAN or IP allowlist.
- Remove or disable unused low-privilege accounts and enforce least privilege on console users.
- Monitor vendor advisories for ePMP and apply subsequent security fixes promptly.
Detection
- Review web server logs for POST requests to the get_chart endpoint containing shell metacharacters.
- Alert on unexpected child processes or shell execution spawned by the web management service.
- Audit authentication logs for readonly or low-privilege accounts accessing management functions.
- Baseline and monitor outbound connections from ePMP devices for signs of post-exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://blog.rapid7.com/2017/12/19/r7-2017-25-cambium-epmp-and-cnpilot-multiple-vulnerabilities/ | Third Party Advisory |
| https://www.exploit-db.com/exploits/43413/ | Third Party AdvisoryVDB Entry |
| https://blog.rapid7.com/2017/12/19/r7-2017-25-cambium-epmp-and-cnpilot-multiple-vulnerabilities/ | Third Party Advisory |
| https://www.exploit-db.com/exploits/43413/ | Third Party AdvisoryVDB Entry |
Track CVE-2017-5255 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-5255), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.