« Back to list

CVE-2019-19843

Status: ModifiedCritical (9.8)—

Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credential fetch via an unauthenticated HTTP request involving a symlink with /tmp and web/user/wps_tool_cache.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (2)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2019-19843",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-01-22T19:15:12.517",
  "references": [
    {
      "url": "https://alephsecurity.com/2020/01/14/ruckus-wireless",
      "tags": [
        "Exploit",
        "Technical Description",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://fahrplan.events.ccc.de/congress/2019/Fahrplan/events/10816.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.ruckuswireless.com/security/299/view/txt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://alephsecurity.com/2020/01/14/ruckus-wireless",
      "tags": [
        "Exploit",
        "Technical Description",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://fahrplan.events.ccc.de/congress/2019/Fahrplan/events/10816.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.ruckuswireless.com/security/299/view/txt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-522"
        },
        {
          "lang": "en",
          "value": "CWE-552"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credential fetch via an unauthenticated HTTP request involving a symlink with /tmp and web/user/wps_tool_cache."
    },
    {
      "lang": "es",
      "value": "Un control de acceso incorrecto en la interfaz web en Ruckus Wireless Unleashed versiones hasta 200.7.10.102.64, permite la extracción de credenciales remota por medio de una petición HTTP no autenticada que involucra un enlace simbólico con /tmp y web/user/wps_tool_cache."
    }
  ],
  "lastModified": "2026-06-17T02:27:20.150",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:ruckuswireless:unleashed:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "020E9499-80F3-47F6-8730-6333A6200987",
              "versionEndExcluding": "200.7.10.202.94"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:ruckuswireless:c110:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A77671DB-6197-4C8D-B667-A0081350E5AF"
            },
            {
              "criteria": "cpe:2.3:h:ruckuswireless:e510:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FBF5C92C-C889-4732-BB00-E6D55613E410"
            },
            {
              "criteria": "cpe:2.3:h:ruckuswireless:h320:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "282C3A1D-711C-4415-B9BE-A9B518204AEB"
            },
            {
              "criteria": "cpe:2.3:h:ruckuswireless:h510:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CB1FAB48-786A-4FB3-AB6D-3118E94E68C7"
            },
            {
              "criteria": "cpe:2.3:h:ruckuswireless:m510:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D4AE7200-4090-4B81-A22F-B8553A014D21"
            },
            {
              "criteria": "cpe:2.3:h:ruckuswireless:r310:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "40D3129E-4C02-484F-96B6-59D76F787D21"
            },
            {
              "criteria": "cpe:2.3:h:ruckuswireless:r320:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "93CE3224-85D2-4039-8F24-BB503DFD42C2"
            },
            {
              "criteria": "cpe:2.3:h:ruckuswireless:r510:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "80B2E8CC-EACE-4A80-9EB1-DADAB8034415"
            },
            {
              "criteria": "cpe:2.3:h:ruckuswireless:r610:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4244947C-538E-4B83-B4F4-3DD4F3C22E83"
            },
            {
              "criteria": "cpe:2.3:h:ruckuswireless:r710:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E95884E9-C6AF-4106-A178-9274AD27EF65"
            },
            {
              "criteria": "cpe:2.3:h:ruckuswireless:r720:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DDFDAF0A-9F5D-4E34-805E-6F27103AAA32"
            },
            {
              "criteria": "cpe:2.3:h:ruckuswireless:t310:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E537F957-DCBF-4C9A-BEB6-A321C091ADF5"
            },
            {
              "criteria": "cpe:2.3:h:ruckuswireless:t610:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "210D55AB-9305-4D0B-B9F0-47889D37373B"
            },
            {
              "criteria": "cpe:2.3:h:ruckuswireless:t710:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A40B9489-D999-4355-953E-36A7F8DEF299"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:ruckuswireless:zonedirector_1200_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F94CA5E2-FA24-4D2B-9650-50B5A39BEFC7",
              "versionEndExcluding": "9.10.2.0.84"
            },
            {
              "criteria": "cpe:2.3:o:ruckuswireless:zonedirector_1200_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "11606EFF-3D0D-4704-9DDA-87064233866C",
              "versionEndExcluding": "9.12.3.0.136",
              "versionStartIncluding": "9.12.0"
            },
            {
              "criteria": "cpe:2.3:o:ruckuswireless:zonedirector_1200_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "16E02881-C6A6-4E06-81C9-9BD711D28988",
              "versionEndExcluding": "10.0.1.0.90",
              "versionStartIncluding": "9.13.0"
            },
            {
              "criteria": "cpe:2.3:o:ruckuswireless:zonedirector_1200_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "59D2E8D2-716C-4B62-ADDC-BD1EB19BDCD5",
              "versionEndExcluding": "10.1.2.0.275",
              "versionStartIncluding": "10.1.0"
            },
            {
              "criteria": "cpe:2.3:o:ruckuswireless:zonedirector_1200_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "44C394D2-4EF4-4C53-8C20-1A29248B79DA",
              "versionEndExcluding": "10.2.1.0.147",
              "versionStartIncluding": "10.2.0"
            },
            {
              "criteria": "cpe:2.3:o:ruckuswireless:zonedirector_1200_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A21CEE8-29D7-4D5F-9A3C-5D27DA512873",
              "versionEndExcluding": "10.3.1.0.21",
              "versionStartIncluding": "10.3.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:ruckuswireless:zonedirector_1200:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0FE0C2B2-D14B-4798-95C4-F911B3B1D88E"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}