Cambium ePMP1000 'get_chart' Shell via Command Injection (v3.1-3.5-RC7)

cve CVE-2017-5255 2 sources, 3 claims · Watch

Metasploit exploit modules writes:
This module exploits an OS Command Injection vulnerability in Cambium ePMP1000 device management portal. It requires any one of the following login credentials - admin/admin, installer/installer, home/home - to set up a reverse netcat shell. The module has been tested on versions 3.1-3.5-RC7. the claim

What each source says

PropertySourceSaidMeans here
Author
author
Exploit-DBMetasploit
receipt
Source
Exploit-DB
Its words
Metasploit
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Metasploit",
  "codes": "CVE-2017-5255",
  "date_added": "2018-01-01",
  "date_published": "2018-01-01",
  "date_updated": "2018-01-01",
  "description": "Cambium ePMP1000 - 'get_chart' Shell via Command Injection (Metasploit)",
  "file": "exploits/cgi/remote/43413.rb",
  "id": "43413",
  "platform": "cgi",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/e6de25d63b2eacc2876b3d0e8a19fc0400734550/modules/exploits/unix/http/epmp1000_get_chart_cmd_shell.rb",
  "tags": "Metasploit Framework (MSF)",
  "type": "remote",
  "verified": "1"
}
—
Platform
platform
not compared
Exploit-DBcgi
receipt
Source
Exploit-DB
Its words
cgi
Read by
field:platform
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Metasploit",
  "codes": "CVE-2017-5255",
  "date_added": "2018-01-01",
  "date_published": "2018-01-01",
  "date_updated": "2018-01-01",
  "description": "Cambium ePMP1000 - 'get_chart' Shell via Command Injection (Metasploit)",
  "file": "exploits/cgi/remote/43413.rb",
  "id": "43413",
  "platform": "cgi",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/e6de25d63b2eacc2876b3d0e8a19fc0400734550/modules/exploits/unix/http/epmp1000_get_chart_cmd_shell.rb",
  "tags": "Metasploit Framework (MSF)",
  "type": "remote",
  "verified": "1"
}
—
Platform
platform
not compared
Metasploit exploit modulesUnix
receipt
Source
Metasploit exploit modules
Its words
Unix
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 18:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "cmd",
  "author": [
    "Karn Ganeshen <KarnGaneshen@gmail.com>"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "This module exploits an OS Command Injection vulnerability in Cambium\n          ePMP1000 device management portal. It requires any one of the following login\n          credentials - admin/admin, installer/installer, home/home - to set up a reverse\n          netcat shell. The module has been tested on versions 3.1-3.5-RC7.",
  "disclosure_date": "2017-12-18",
  "fullname": "exploit/unix/http/epmp1000_get_chart_cmd_shell",
  "is_install_path": true,
  "mod_time": "2026-04-02 17:30:43 +0000",
  "name": "Cambium ePMP1000 'get_chart' Shell via Command Injection (v3.1-3.5-RC7)",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "unknown-reliability"
    ],
    "SideEffects": [
      "unknown-side-effects"
    ],
    "Stability": [
      "unknown-stability"
    ]
  },
  "path": "/modules/exploits/unix/http/epmp1000_get_chart_cmd_shell.rb",
  "platform": "Unix",
  "post_auth": true,
  "rank": 600,
  "ref_name": "unix/http/epmp1000_get_chart_cmd_shell",
  "references": [
    "CVE-2017-5255",
    "URL-https://www.rapid7.com/blog/post/2017/12/19/r7-2017-25-cambium-epmp-and-cnpilot-multiple-vulnerabilities"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "CMD"
  ],
  "type": "exploit"
}
—
Rank
rank
Metasploit exploit modules600
Excellent. Cannot crash the service. A memory-corruption exploit does not qualify.
receipt
Source
Metasploit exploit modules
Its words
600
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 18:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "cmd",
  "author": [
    "Karn Ganeshen <KarnGaneshen@gmail.com>"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "This module exploits an OS Command Injection vulnerability in Cambium\n          ePMP1000 device management portal. It requires any one of the following login\n          credentials - admin/admin, installer/installer, home/home - to set up a reverse\n          netcat shell. The module has been tested on versions 3.1-3.5-RC7.",
  "disclosure_date": "2017-12-18",
  "fullname": "exploit/unix/http/epmp1000_get_chart_cmd_shell",
  "is_install_path": true,
  "mod_time": "2026-04-02 17:30:43 +0000",
  "name": "Cambium ePMP1000 'get_chart' Shell via Command Injection (v3.1-3.5-RC7)",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "unknown-reliability"
    ],
    "SideEffects": [
      "unknown-side-effects"
    ],
    "Stability": [
      "unknown-stability"
    ]
  },
  "path": "/modules/exploits/unix/http/epmp1000_get_chart_cmd_shell.rb",
  "platform": "Unix",
  "post_auth": true,
  "rank": 600,
  "ref_name": "unix/http/epmp1000_get_chart_cmd_shell",
  "references": [
    "CVE-2017-5255",
    "URL-https://www.rapid7.com/blog/post/2017/12/19/r7-2017-25-cambium-epmp-and-cnpilot-multiple-vulnerabilities"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "CMD"
  ],
  "type": "exploit"
}
—
Type
type
Exploit-DBremote
receipt
Source
Exploit-DB
Its words
remote
Read by
field:type
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Metasploit",
  "codes": "CVE-2017-5255",
  "date_added": "2018-01-01",
  "date_published": "2018-01-01",
  "date_updated": "2018-01-01",
  "description": "Cambium ePMP1000 - 'get_chart' Shell via Command Injection (Metasploit)",
  "file": "exploits/cgi/remote/43413.rb",
  "id": "43413",
  "platform": "cgi",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/e6de25d63b2eacc2876b3d0e8a19fc0400734550/modules/exploits/unix/http/epmp1000_get_chart_cmd_shell.rb",
  "tags": "Metasploit Framework (MSF)",
  "type": "remote",
  "verified": "1"
}
—
Verified
verified
Exploit-DBtrue
receipt
Source
Exploit-DB
Its words
1
Read by
field:verified
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Metasploit",
  "codes": "CVE-2017-5255",
  "date_added": "2018-01-01",
  "date_published": "2018-01-01",
  "date_updated": "2018-01-01",
  "description": "Cambium ePMP1000 - 'get_chart' Shell via Command Injection (Metasploit)",
  "file": "exploits/cgi/remote/43413.rb",
  "id": "43413",
  "platform": "cgi",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/e6de25d63b2eacc2876b3d0e8a19fc0400734550/modules/exploits/unix/http/epmp1000_get_chart_cmd_shell.rb",
  "tags": "Metasploit Framework (MSF)",
  "type": "remote",
  "verified": "1"
}
—

exploit

Cambium ePMP1000 'get_chart' Shell via Command Injection (v3.1-3.5-RC7)
zetlyn/cve-metasploit · 2017-12-18
platform Unix rank 600 source
Cambium ePMP1000 'ping' Shell via Command Injection (up to v2.5)
zetlyn/cve-metasploit · 2015-11-28
platform Unix rank 600 source
Cambium ePMP1000 - 'get_chart' Shell via Command Injection (Metasploit)
zetlyn/cve-exploitdb · 2018-01-01
author Metasploit platform cgi type remote verified true source