← Back to browse · API

CVE-2022-1357

Severity
CRITICAL
CVSS
9.8
EPSS
0.01713
Risk score
39.8
CISA KEV
No
PoC
No
Published
2022-05-17
Modified
2025-04-16
First seen
2026-08-07
Aliases
EUVD-2022-24678, GHSA-86HF-JFR6-R7P7
Products
Cambium Networks:cnMaestro unspecified <2.4.2-r29, Cambium Networks:cnMaestro unspecified <3.0.0-r34, Cambium Networks:cnMaestro unspecified <3.0.3-r32
Sources
euvd EUVD-2022-24678

Description

The affected On-Premise cnMaestro allows an unauthenticated attacker to access the cnMaestro server and execute arbitrary code in the privileges of the web server. This lack of validation could allow an attacker to append arbitrary data to the logger command.

References