Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-100767. PoCs published by Karn Ganeshen.
AI-analyzed exploit summary This exploit demonstrates an OS command injection vulnerability in Cambium Networks ePMP 1000 devices, allowing authenticated users (including low-privileged 'installer' and 'home' users) to execute arbitrary system commands via the Ping and Traceroute functions. The PoC includes HTTP requests that inject commands to dump the /etc/passwd file.
Description
Cambium ePMP 1000 - Multiple Vulnerabilities
Exploits (1)
This exploit demonstrates an OS command injection vulnerability in Cambium Networks ePMP 1000 devices, allowing authenticated users (including low-privileged 'installer' and 'home' users) to execute arbitrary system commands via the Ping and Traceroute functions. The PoC includes HTTP requests that inject commands to dump the /etc/passwd file.