ZeroHour

CVE-2017-5263

CVSS 3.0
8.0 high
EPSS
<1%p22
Published
()
Modified
Description

Versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware lack CSRF controls that can mitigate the effects of CSRF attacks, which are most typically implemented as randomized per-session tokens associated with any web application function, especially destructive ones.

Vendors
cambiumnetworks
Products
cnpilot r190v firmware, cnpilot e410 firmware, cnpilot r190n firmware, cnpilot e400 firmware, cnpilot e600 firmware
Weakness
CWE-352
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.