VYPR
Unrated severityNVD Advisory· Published Jan 22, 2020· Updated Aug 5, 2024

CVE-2019-19842

CVE-2019-19842

Description

emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=spectra-analysis to admin/_cmdstat.jsp via the mac attribute.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unauthenticated command injection in Ruckus Wireless Unleashed allows remote OS command execution via a crafted POST request to admin/_cmdstat.jsp.

Vulnerability

The vulnerability resides in the emfd component of Ruckus Wireless Unleashed firmware through version 200.7.10.102.64. It allows remote attackers to execute arbitrary OS commands by sending a POST request to admin/_cmdstat.jsp with the attribute xcmd=spectra-analysis and a malicious mac parameter. This is a command injection flaw that requires no authentication [1].

Exploitation

An attacker can exploit this vulnerability by sending a crafted HTTP POST request to the target device. The mac parameter is injectable with command syntax; the xcmd=spectra-analysis triggers the vulnerable code path. No prior authentication or user interaction is needed, making it exploitable pre-authentication from any network-accessible location [1][3].

Impact

Successful exploitation results in arbitrary OS command execution with root privileges, leading to full compromise of the access point. An attacker can read/modify configurations, exfiltrate data, install malware, or pivot to internal networks [1].

Mitigation

Ruckus has released a firmware update (200.7.10.102.64 or later) to address this issue [1]. Users should upgrade to the latest version. If patching is not possible, restrict network access to the management interface and disable WAN-facing services.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.