← Vulnerability feed

Vulnerability record · CVE-2017-5255 · published 20 December 2017

CVE-2017-5255: Cambium ePMP firmware command injection in get_chart web console

Cambiumnetworks · Epmp 1000 Firmware

Cambium Networks ePMP firmware version 3.5 and prior fails to sanitize certain parameters on the web management console. Any authenticated user, including the low-privilege readonly account, can inject shell meta-characters via a crafted POST to the get_chart function and execute OS commands as root.

8.8 CVSS 3.0 High EPSS 74% · top 0.5% CWE-78 · OS command injection
8.8CVSS 3.0 base score, v2 9.0
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows any authenticated user (including the otherwise low-privilege readonly user) to inject shell meta-characters as part of a specially-crafted POST request to the get_chart function and run OS-level commands, effectively as root.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityNetwork-reachable root command injection with a low-privilege authentication requirement and public exploit code, though not observed in KEV or ransomware campaigns.

What it is

Cambium Networks ePMP firmware version 3.5 and prior fails to sanitize certain parameters on the web management console. Any authenticated user, including the low-privilege readonly account, can inject shell meta-characters via a crafted POST to the get_chart function and execute OS commands as root.

Impact

An attacker with any valid account gains root-level command execution on the affected access point, allowing full device compromise, configuration changes, and use as a network foothold.

Attack surface

Reachable over the network through the web management console; the attacker must be authenticated but needs no user interaction, and even the lowest-privilege readonly role suffices.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.74556, ~99.5th percentile) and public exploit code exists via Exploit-DB, indicating active interest and easy weaponization.

What to do

  • Upgrade ePMP firmware beyond version 3.5 to a vendor-supported release.
  • Restrict web management console access to a trusted management VLAN or IP allowlist.
  • Remove or disable unused low-privilege accounts and enforce least privilege on console users.
  • Monitor vendor advisories for ePMP and apply subsequent security fixes promptly.

Detection

  • Review web server logs for POST requests to the get_chart endpoint containing shell metacharacters.
  • Alert on unexpected child processes or shell execution spawned by the web management service.
  • Audit authentication logs for readonly or low-privilege accounts accessing management functions.
  • Baseline and monitor outbound connections from ePMP devices for signs of post-exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-5255 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2017-5254Cambium ePMP firmware privilege escalation via client-side password change bypassCambium Networks ePMP firmware version 3.5 and earlier allows non-administrative users 'installer' and 'home' to change passwords for other accounts,…EPSS 54%analysed5.4CVE-2017-5256Cambiumnetworks epmp 1000 firmware cross-site scripting vulnerabilityIn version 3.5 and prior of Cambium Networks ePMP firmware, all authenticated users have the ability to update the Device Name and System Description…EPSS 0.50%5.4CVE-2017-5257Cambiumnetworks epmp 1000 firmware cross-site scripting vulnerabilityIn version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows (or guesses) the SNMP read/write (RW) community string can insert X…EPSS 0.52%5.4CVE-2017-5258Cambiumnetworks epmp 1000 firmware cross-site scripting vulnerabilityIn version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows or can guess the RW community string can provide a URL for a config…EPSS 0.54%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed7.8CVE-2026-83549SonicWall SMA1000 AMC OS Command InjectionThe SMA1000 Appliance Management Console contains an OS command injection flaw (CWE-78) that lets an authenticated administrator execute arbitrary op…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2017-5255), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.