CVE-2017-5255 is a command injection vulnerability in Cambium Networks ePMP firmware version 3.5 and prior. The web management console fails to properly sanitize input for certain parameters in the get_chart function, allowing any authenticated user, including those with readonly privileges, to inject shell meta-characters via a specially-crafted POST request. This enables execution of arbitrary OS-level commands as root.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (Ruby file) that exploits a command injection vulnerability (CVE-2017-5255) in the Cambium ePMP1000 device management portal (firmware <2.5). The exploit requires valid credentials (admin/admin, installer/installer, or home/home) and targets the web interface, typically on port 80. The module first verifies the target is a vulnerable ePMP1000 device, then authenticates, and finally exploits the 'ping' functionality by injecting a payload into the 'packets_num' parameter of the /admin/ping endpoint. The default payload is a reverse netcat shell, granting the attacker remote command execution. The code is operational and weaponized, leveraging Metasploit's framework for payload handling and session management. The only file present is the exploit module itself, written in Ruby.
This repository contains a single Metasploit module targeting Cambium ePMP1000 wireless device management portals (firmware versions 3.1 to 3.5-RC7) vulnerable to OS command injection (CVE-2017-5255). The exploit requires valid credentials (admin/admin, installer/installer, or home/home) and leverages the '/cgi-bin/luci/;stok=<stok_value>/admin/get_chart' endpoint to inject commands via POST parameters. The module fingerprints the device, authenticates, and then delivers a payload (by default, a reverse netcat shell) to gain remote shell access. The code is written in Ruby and follows standard Metasploit module structure, with clear separation of fingerprinting, authentication, exploitation, and payload delivery logic. The main attack vector is network-based, exploiting a web interface over HTTP. The endpoints '/cgi-bin/luci' and '/cgi-bin/luci/;stok=<stok_value>/admin/get_chart' are key to the exploit's operation.
This repository contains a single Metasploit auxiliary module targeting Cambium ePMP 1000 devices running firmware versions below 2.5. The module exploits a command injection vulnerability (CVE-2017-5255) in the device's web management portal. It requires valid credentials (admin/admin, installer/installer, or home/home) to authenticate. The exploit works by injecting arbitrary system commands into the 'packets_num' parameter of a POST request to the device's ping functionality. The module allows the user to specify any command to execute (default: 'id; pwd'), and saves the output to a loot file. The code is written in Ruby and is structured as a standard Metasploit module, with options for target port, credentials, and command. The main attack vector is network-based, targeting the HTTP interface of the device. No hardcoded IPs or URLs are present, but the module is designed to be used against accessible Cambium ePMP 1000 devices.
This repository contains a single Metasploit auxiliary module targeting Cambium ePMP 1000 wireless devices (firmware versions 3.1 to 3.5-RC7) vulnerable to OS command injection (CVE-2017-5255). The exploit requires valid credentials (admin, installer, or home accounts) and interacts with the device's HTTP management interface, typically on port 80. The module injects arbitrary system commands into the 'timestamp' parameter of the 'get_chart' endpoint via a POST request. The output of the executed command is returned and saved as loot in Metasploit. The code is written in Ruby and is structured as a standard Metasploit module, with options for target port, credentials, and command to execute. The main exploit logic is in the 'cmd_exec' function, which crafts and sends the malicious request after authenticating to the device.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.