Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2585▼ 303 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

33 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.7)0.52%—Ruckus UnleashedAI26/3/202617/6/2026
Ruckus Unleashed contains a remote code execution vulnerability in the web-based management interface that allows authenticated remote attackers to execute arbitrary code on the system when gateway mode is enabled. Attackers can exploit this vulnerability by sending specially crafted requests through the management…
AplazadaAlta (7.5)0.58%—LT UnleashedAI12/12/202530/9/2026
The LT Unleashed plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.1 via the 'template' parameter in the `book` shortcode due to insufficient path sanitization. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and…
AnalizadaMedia (6.1)0.22%—Ruckuswireless Ruckus Unleashed25/11/202517/6/2026
A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp.
AnalizadaAlta (7.2)1.1%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where the authenticated configuration endpoint `/admin/_conf.jsp` writes the Wi-Fi guest password to memory with snprintf using the attacker-supplied value as the format…
AnalizadaCrítica (9.1)1.1%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled input to the shell without adequate validation, enabling a remote attacker to specify a target by MAC address and execute…
AnalizadaCrítica (9.8)1.3%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to snprintf as the format string. A remote attacker can exploit this flaw either by sending a crafted…
AnalizadaCrítica (9.8)1.00%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates outside permitted directories, allowing a remote unauthenticated…
AnalizadaMedia (6.3)0.37%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where an authenticated request to the management endpoint `/admin/_cmdstat.jsp` discloses the administrator password in a trivially reversible obfuscated form. The same…
AnalizadaMedia (5.3)0.53%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remote attacker to upload or retrieve arbitrary files from writable…
AnalizadaCrítica (9.1)0.83%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where a hidden debug script `.ap_debug.sh` invoked from the restricted CLI does not properly sanitize its input, allowing an authenticated attacker to execute arbitrary…
AnalizadaAlta (8.8)0.51%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the passphrase requirement for a hidden CLI command `!v54!` via a management API call and then invoke it to escape the…
ModificadaCrítica (9.8)2.5%—Ruckuswireless Unleashed Firmware28/7/202017/6/2026
emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to achieve command injection via a crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s, T610, T710, and T710s…
ModificadaAlta (7.5)2.4%—Ruckuswireless Unleashed Firmware28/7/202017/6/2026
Incorrect access control in webs in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to leak system information (that can be used for a jailbreak) via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300,…
ModificadaCrítica (9.8)2.1%—Ruckuswireless Unleashed Firmware28/7/202017/6/2026
rkscli in Ruckus Wireless Unleashed through 200.7.10.92 allows a remote attacker to achieve command injection and jailbreak the CLI via a crafted CLI command. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s, T610, T710, and…
ModificadaCrítica (9.8)3.6%—Ruckuswireless Unleashed Firmware28/7/202017/6/2026
A stack buffer overflow in webs in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to execute code via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s,…
ModificadaAlta (7.5)1.9%—Ruckuswireless Unleashed Firmware28/7/202017/6/2026
Insecure permissions in emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allow a remote attacker to overwrite admin credentials via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d,…
ModificadaAlta (7.5)2.3%—Ruckuswireless Unleashed Firmware28/7/202017/6/2026
webs in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to cause a denial of service (Segmentation fault) to the webserver via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c,…
ModificadaMedia (6.1)1.3%—Ruckuswireless Unleashed Firmware28/7/202017/6/2026
An XSS issue in emfd in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to execute JavaScript code via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s,…
ModificadaCrítica (9.8)3.3%—Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware23/1/202017/6/2026
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=import-category to admin/_cmdstat.jsp via the uploadFile attribute.
ModificadaCrítica (9.8)24%—Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware23/1/202017/6/2026
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=get-platform-depends to admin/_cmdstat.jsp via the uploadFile attribute.
ModificadaMedia (5.3)2.0%—Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware23/1/202017/6/2026
Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote information disclosure of bin/web.conf via HTTP requests.
ModificadaAlta (7.5)1.8%—Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware23/1/202017/6/2026
SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of service via the server attribute to the tools/_rcmdstat.jsp URI.
ModificadaCrítica (9.8)5.0%—Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware22/1/202017/6/2026
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=spectra-analysis to admin/_cmdstat.jsp via the mac attribute.
ModificadaCrítica (9.8)3.3%—Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware22/1/202017/6/2026
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=packet-capture to admin/_cmdstat.jsp via the mac attribute.
ModificadaCrítica (9.8)4.1%—Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware22/1/202017/6/2026
A stack-based buffer overflow in zap_parse_args in zap.c in zap in Ruckus Unleashed through 200.7.10.102.64 allows remote code execution via an unauthenticated HTTP request.