CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field on the Wireless Admin screen.
2020-05-05T18:15:13.490
2024-11-21T05:39:31.547
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | commscope | ruckus_zoneflex_r500_firmware | - | Yes |
Hardware | commscope | ruckus_zoneflex_r500 | - | No |