Cambiumnetworks
17 CVEs tracked since 2017. Since Dec 2017, none of them reached CISA KEV.
Cambiumnetworks CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2017-12 | 10 | 0 |
| 2018-01 | null or fewer | |
| 2018-02 | null or fewer | |
| 2018-03 | null or fewer | |
| 2018-04 | null or fewer | |
| 2018-05 | null or fewer | |
| 2018-06 | null or fewer | |
| 2018-07 | null or fewer | |
| 2018-08 | null or fewer | |
| 2018-09 | null or fewer | |
| 2018-10 | null or fewer | |
| 2018-11 | null or fewer | |
| 2018-12 | null or fewer | |
| 2019-01 | null or fewer | |
| 2019-02 | null or fewer | |
| 2019-03 | null or fewer | |
| 2019-04 | null or fewer | |
| 2019-05 | null or fewer | |
| 2019-06 | null or fewer | |
| 2019-07 | null or fewer | |
| 2019-08 | null or fewer | |
| 2019-09 | null or fewer | |
| 2019-10 | null or fewer | |
| 2019-11 | null or fewer | |
| 2019-12 | null or fewer | |
| 2020-01 | null or fewer | |
| 2020-02 | null or fewer | |
| 2020-03 | null or fewer | |
| 2020-04 | null or fewer | |
| 2020-05 | null or fewer | |
| 2020-06 | null or fewer | |
| 2020-07 | null or fewer | |
| 2020-08 | null or fewer | |
| 2020-09 | null or fewer | |
| 2020-10 | null or fewer | |
| 2020-11 | null or fewer | |
| 2020-12 | null or fewer | |
| 2021-01 | null or fewer | |
| 2021-02 | null or fewer | |
| 2021-03 | null or fewer | |
| 2021-04 | null or fewer | |
| 2021-05 | null or fewer | |
| 2021-06 | null or fewer | |
| 2021-07 | null or fewer | |
| 2021-08 | null or fewer | |
| 2021-09 | null or fewer | |
| 2021-10 | null or fewer | |
| 2021-11 | null or fewer | |
| 2021-12 | null or fewer | |
| 2022-01 | null or fewer | |
| 2022-02 | null or fewer | |
| 2022-03 | null or fewer | |
| 2022-04 | null or fewer | |
| 2022-05 | 7 | 0 |
Products
The products that kept showing up in Cambiumnetworks's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Cambiumnetworks.
- CVE-2023-6691Code Injection vulnerability in Cambium ePMP Force 300-257.8
- CVE-2022-35908Cambium Enterprise Wi-Fi System Software before 6.4.2 does not sanitize the ping host argument in device-agent.8.8
- CVE-2022-1362Cambium Networks cnMaestro OS Command Injection5.0
- CVE-2022-1361Cambium Networks cnMaestro SQL Injection7.4
- CVE-2022-1360Cambium Networks cnMaestro OS Command Injection8.2
- CVE-2022-1359Cambium Networks cnMaestro Path Traversal5.7
- CVE-2022-1358Cambium Networks cnMaestro SQL Injection5.9
- CVE-2022-1356Cambium Networks cnMaestro use of Potentially Dangerous Function7.1
- CVE-2022-1357Cambium Networks cnMaestro OS Command Injection9.8
- CVE-2020-9022An issue was discovered on Xirrus XR520, XR620, XR2436, and XH2-120 devices. The cgi-bin/ViewPage.cgi user parameter allows XSS.6.1
- CVE-2017-5263Versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware lack CSRF controls that can mitigate the effects of CSRF attacks, which are most typically implemented as randomized per-session tok...8.0
- CVE-2017-5257In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows (or guesses) the SNMP read/write (RW) community string can insert XSS strings in certain SNMP OIDs which will execu...5.4
- CVE-2017-5254In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passwords for other accounts, including admin, after ...8.8
- CVE-2017-5258In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows or can guess the RW community string can provide a URL for a configuration file over SNMP with XSS strings in certa...5.4
- CVE-2017-5262In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access to sensitive information by OID reference.8.0
The record
- Peak rank
- #28 in Dec 2017
- Busiest month shown
- Dec 2017, 10 CVEs
- Months with a KEV entry
- 0 since Dec 2017
- Monthly snapshots
- 2 since 2017