Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoint), injecting arbitrary commands that will be executed as root user via web.py.
2020-10-26T20:15:14.473
2024-11-21T05:20:23.883
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | commscope | ruckus_vriot | ≤ 1.5.1.0.21 | Yes |
Hardware | commscope | ruckus_iot_module | - | No |