Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.22% | — | Ruckuswireless Ruckus Unleashed | 25/11/2025 | 17/6/2026 | A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp. | |
| Analizada | Alta (7.2) | 1.1% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where the authenticated configuration endpoint `/admin/_conf.jsp` writes the Wi-Fi guest password to memory with snprintf using the attacker-supplied value as the format… | |
| Analizada | Crítica (9.1) | 1.1% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled input to the shell without adequate validation, enabling a remote attacker to specify a target by MAC address and execute… | |
| Analizada | Crítica (9.8) | 1.3% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to snprintf as the format string. A remote attacker can exploit this flaw either by sending a crafted… | |
| Analizada | Crítica (9.8) | 1.00% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates outside permitted directories, allowing a remote unauthenticated… | |
| Analizada | Media (6.3) | 0.37% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where an authenticated request to the management endpoint `/admin/_cmdstat.jsp` discloses the administrator password in a trivially reversible obfuscated form. The same… | |
| Analizada | Media (5.3) | 0.53% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remote attacker to upload or retrieve arbitrary files from writable… | |
| Analizada | Crítica (9.1) | 0.83% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where a hidden debug script `.ap_debug.sh` invoked from the restricted CLI does not properly sanitize its input, allowing an authenticated attacker to execute arbitrary… | |
| Analizada | Alta (8.8) | 0.51% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the passphrase requirement for a hidden CLI command `!v54!` via a management API call and then invoke it to escape the… |