CVE Tools

Cambiumnetworks

17 CVEs tracked since 2017. Since Dec 2017, none of them reached CISA KEV.

Cambiumnetworks CVEs per month

Dec 2017 to May 2022. Point at a month, or focus the strip and use the arrow keys.
Cambiumnetworks CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2017-12100
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-0570

Products

The products that kept showing up in Cambiumnetworks's monthly top three, with their CVEs summed over those months.

  1. Cnmaestro71 month
  2. Cnpilot E410 Firmware51 month
  3. Cnpilot E600 Firmware51 month
  4. Cnpilot R190N Firmware51 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Cambiumnetworks.

  1. CVE-2023-6691Code Injection vulnerability in Cambium ePMP Force 300-257.8
  2. CVE-2022-35908Cambium Enterprise Wi-Fi System Software before 6.4.2 does not sanitize the ping host argument in device-agent.8.8
  3. CVE-2022-1362Cambium Networks cnMaestro OS Command Injection5.0
  4. CVE-2022-1361Cambium Networks cnMaestro SQL Injection7.4
  5. CVE-2022-1360Cambium Networks cnMaestro OS Command Injection8.2
  6. CVE-2022-1359Cambium Networks cnMaestro Path Traversal5.7
  7. CVE-2022-1358Cambium Networks cnMaestro SQL Injection5.9
  8. CVE-2022-1356Cambium Networks cnMaestro use of Potentially Dangerous Function7.1
  9. CVE-2022-1357Cambium Networks cnMaestro OS Command Injection9.8
  10. CVE-2020-9022An issue was discovered on Xirrus XR520, XR620, XR2436, and XH2-120 devices. The cgi-bin/ViewPage.cgi user parameter allows XSS.6.1
  11. CVE-2017-5263Versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware lack CSRF controls that can mitigate the effects of CSRF attacks, which are most typically implemented as randomized per-session tok...8.0
  12. CVE-2017-5257In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows (or guesses) the SNMP read/write (RW) community string can insert XSS strings in certain SNMP OIDs which will execu...5.4
  13. CVE-2017-5254In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passwords for other accounts, including admin, after ...8.8
  14. CVE-2017-5258In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows or can guess the RW community string can provide a URL for a configuration file over SNMP with XSS strings in certa...5.4
  15. CVE-2017-5262In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access to sensitive information by OID reference.8.0

The record

Peak rank
#28 in Dec 2017
Busiest month shown
Dec 2017, 10 CVEs
Months with a KEV entry
0 since Dec 2017
Monthly snapshots
2 since 2017
Cambiumnetworks's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store