← Back

CVE-2017-5256

nvd nist
Published: Dec 20, 2017Modified: May 13, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

In version 3.5 and prior of Cambium Networks ePMP firmware, all authenticated users have the ability to update the Device Name and System Description fields in the web administration console, and those fields are vulnerable to persistent cross-site scripting (XSS) injection.

Affected (2)

2 products
Epmp 1000 Firmware
Epmp 2000 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 3.5
Running on/withPlatform Versions
Cambiumnetworks
Epmp 1000
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 3.5
Running on/withPlatform Versions
Cambiumnetworks
Epmp 2000
All versions

Timeline

No history available yet.