CVE-2017-5255

CVE-2017-5255

In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows any authenticated user (including the otherwise low-privilege readonly user) to inject shell meta-characters as part of a specially-crafted POST request to the get_chart function and run OS-level commands, effectively as root.

Source: CVE-2017-5255

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다