Skip to main content

CVE-2017-5259

8.8
HIGHCVSS v3.1 Base Score
66.34%
MEDIUM RiskEPSS (99th percentile)

In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or-hostname>/adm/syscmd.asp.

Published: 12/20/2017
Modified: 5/13/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.8HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2 Score

9

AV:N/AC:L/Au:S/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

66.34%MEDIUM Exploitation Risk
99th percentile

This vulnerability has a 66.34% probability of being exploited in the next 30 days, ranking higher than 99% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-489)

Similar SeverityHIGH