Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-5262.
PoCs published by Karn Ganeshen, including Metasploit module auxiliary/scanner/snmp/cnpilot_r_snmp_loot.
AI-analyzed exploit summary This Metasploit module exploits an access control flaw in Cambium cnPilot r200/r201 devices to extract sensitive information via SNMP Read-Only (RO) community string. It enumerates system details, admin credentials, SNMP settings, WiFi configurations, and SIP account information.
Description
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access to sensitive information by OID reference.
Exploits (1)
This Metasploit module exploits an access control flaw in Cambium cnPilot r200/r201 devices to extract sensitive information via SNMP Read-Only (RO) community string. It enumerates system details, admin credentials, SNMP settings, WiFi configurations, and SIP account information.
References (1)
Scores
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H