Posted by disclosure via Fulldisclosure on Sep 26 0day Rubbish Research Team is publicly disclosing a vulnerability in the Cambium cnMatrix EX3024F managed switch, firmware 6.2.1-r4. Type: OS command injection (CWE-78, with CWE-20 bearing on it because percent-decoding is the only processing applied; CWE-250/CWE-269 bear on remediation priority).
[0day-rubbish] Cambium cnMatrix EX3024F 6.2.1-r4 SSL CSR COMMON_NAME command injection to root RCE (7.2)
About this summary. This is a short, independently written summary of an article first published by Full Disclosure. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/fulldisclosure/2026/Sep/70
Source attribution: headline and facts are from Full Disclosure (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.


