CVE-2019-19841
Description
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=packet-capture to admin/_cmdstat.jsp via the mac attribute.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Ruckus Wireless Unleashed access points are vulnerable to pre-authentication OS command injection via a crafted POST request to admin/_cmdstat.jsp.
Vulnerability
The vulnerability resides in the emfd component of Ruckus Wireless Unleashed firmware versions through 200.7.10.102.64. It allows remote attackers to execute arbitrary OS commands by sending a POST request to the /admin/_cmdstat.jsp endpoint with the parameter xcmd=packet-capture and a crafted mac attribute. No authentication is required to trigger the vulnerability. [1]
Exploitation
An attacker can exploit this vulnerability without any prior authentication. The attacker sends a POST request to admin/_cmdstat.jsp with the xcmd parameter set to packet-capture and the mac parameter containing the OS command to be executed. The command is injected into the system and executed by emfd. [1]
Impact
Successful exploitation results in remote code execution as the root user, giving the attacker full control over the affected access point. This can lead to data exfiltration, network pivoting, and further compromise of the network. [1]
Mitigation
As of the publication date (2020-01-22), no official patch has been released in the available references. Users should monitor Ruckus security advisories and upgrade to a patched firmware version if released. If no patch is available, limiting network access to the management interface can reduce exposure. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Ruckus Wireless/Unleasheddescription
- Range: <=200.7.10.102.64
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- alephsecurity.com/2020/01/14/ruckus-wirelessmitrex_refsource_MISC
- fahrplan.events.ccc.de/congress/2019/Fahrplan/events/10816.htmlmitrex_refsource_MISC
- www.ruckuswireless.com/security/299/view/txtmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.