Description
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available in the normal web administrative console for the 'user' account, the configuration file is accessible via direct object reference (DRO) at http://<device-ip-or-hostname>/goform/down_cfg_file by this otherwise low privilege 'user' account.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Subscriptions
Cambiumnetworks
Subscribe
Cnpilot E400
Subscribe
Cnpilot E400 Firmware
Subscribe
Cnpilot E410
Subscribe
Cnpilot E410 Firmware
Subscribe
Cnpilot E600
Subscribe
Cnpilot E600 Firmware
Subscribe
Cnpilot R190n
Subscribe
Cnpilot R190n Firmware
Subscribe
Cnpilot R190v
Subscribe
Cnpilot R190v Firmware
Subscribe
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2024-08-05T14:55:35.713Z
Reserved: 2017-01-09T00:00:00.000Z
Link: CVE-2017-5260
No data.
Status : Deferred
Published: 2017-12-20T22:29:00.557
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-5260
No data.
OpenCVE Enrichment
No data.