Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the service API by using a backdoor value as the Authorization header.
2020-10-26T20:15:14.537
2024-11-21T05:20:24.057
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | commscope | ruckus_vriot | ≤ 1.5.1.0.21 | Yes |
Hardware | commscope | ruckus_iot_module | - | No |