VYPR
Unrated severityNVD Advisory· Published Jan 23, 2020· Updated Aug 5, 2024

CVE-2019-19835

CVE-2019-19835

Description

SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of service via the server attribute to the tools/_rcmdstat.jsp URI.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An SSRF vulnerability in Ruckus Wireless Unleashed firmware through 200.7.10.102.64 allows remote denial of service via crafted requests to tools/_rcmdstat.jsp.

Vulnerability

An SSRF (Server-Side Request Forgery) vulnerability exists in the AjaxRestrictedCmdStat component of Ruckus Wireless Unleashed firmware through version 200.7.10.102.64 [1]. The vulnerability is triggered by sending a crafted server attribute to the tools/_rcmdstat.jsp URI, allowing a remote attacker to cause a denial of service [1][2]. Affected devices include indoor and outdoor access points such as R510, R610, R710, and many others running the vulnerable firmware [1].

Exploitation

An attacker does not require authentication and can exploit this SSRF over the network [1]. By sending a malicious HTTP request to the tools/_rcmdstat.jsp endpoint with a crafted server parameter, the vulnerable component makes an outbound request to a destination controlled by the attacker, leading to a denial of service condition [1][2]. No user interaction is needed [1].

Impact

Successful exploitation results in a denial of service, impacting the availability of the affected access point [1][2]. The attacker does not gain code execution or data access from this specific vulnerability, but it can be chained with other vulnerabilities for more severe impacts [1]. The CIA impact is limited to availability [1].

Mitigation

Ruckus has not released a patch for this specific vulnerability as of the publication date [1][2]. Users are advised to restrict network access to the management interface of affected devices and monitor for firmware updates from Ruckus [1]. The affected firmware version 200.7.10.102.64 is end-of-life for some devices [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.