In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users installer and home have the capability of changing passwords for other accounts, including admin, after disabling a client-side protection mechanism.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Epmp_1000_firmware | Cambiumnetworks | * | 3.5 (including) |