Ruckuswireless
Ruckuswireless Unleashed: vulnerabilidades y CVE
Ruckuswireless Unleashed tiene 10 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses0
Críticas7
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-19839 | Crítica (9.8) | 3.3% | — | 23 ene 2020 | emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=import-category to admin/_cmdstat.jsp via the uploadFile attribute. |
| CVE-2019-19838 | Crítica (9.8) | 24% | — | 23 ene 2020 | emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=get-platform-depends to admin/_cmdstat.jsp via the uploadFile attribute. |
| CVE-2019-19837 | Media (5.3) | 2.0% | — | 23 ene 2020 | Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote information disclosure of bin/web.conf via HTTP requests. |
| CVE-2019-19835 | Alta (7.5) | 1.8% | — | 23 ene 2020 | SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of service via the server attribute to the tools/_rcmdstat.jsp URI. |
| CVE-2019-19842 | Crítica (9.8) | 5.0% | — | 22 ene 2020 | emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=spectra-analysis to admin/_cmdstat.jsp via the mac attribute. |
| CVE-2019-19841 | Crítica (9.8) | 3.3% | — | 22 ene 2020 | emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=packet-capture to admin/_cmdstat.jsp via the mac attribute. |
| CVE-2019-19840 | Crítica (9.8) | 4.1% | — | 22 ene 2020 | A stack-based buffer overflow in zap_parse_args in zap.c in zap in Ruckus Unleashed through 200.7.10.102.64 allows remote code execution via an unauthenticated HTTP request. |
| CVE-2019-19843 | Crítica (9.8) | 1.8% | — | 22 ene 2020 | Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credential fetch via an unauthenticated HTTP request involving a symlink with /tmp and… |
| CVE-2019-19836 | Crítica (9.8) | 3.6% | — | 22 ene 2020 | AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote code execution via a POST request that uses tools/_rcmdstat.jsp to write to a specified filename. |
| CVE-2019-19834 | Alta (7.2) | 2.2% | — | 22 ene 2020 | Directory Traversal in ruckus_cli2 in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote attacker to jailbreak the CLI via enable->debug->script->exec with ../../../bin/sh as the parameter. |