CVE-2019-19842
Description
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=spectra-analysis to admin/_cmdstat.jsp via the mac attribute.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Unauthenticated command injection in Ruckus Wireless Unleashed allows remote OS command execution via a crafted POST request to admin/_cmdstat.jsp.
Vulnerability
The vulnerability resides in the emfd component of Ruckus Wireless Unleashed firmware through version 200.7.10.102.64. It allows remote attackers to execute arbitrary OS commands by sending a POST request to admin/_cmdstat.jsp with the attribute xcmd=spectra-analysis and a malicious mac parameter. This is a command injection flaw that requires no authentication [1].
Exploitation
An attacker can exploit this vulnerability by sending a crafted HTTP POST request to the target device. The mac parameter is injectable with command syntax; the xcmd=spectra-analysis triggers the vulnerable code path. No prior authentication or user interaction is needed, making it exploitable pre-authentication from any network-accessible location [1][3].
Impact
Successful exploitation results in arbitrary OS command execution with root privileges, leading to full compromise of the access point. An attacker can read/modify configurations, exfiltrate data, install malware, or pivot to internal networks [1].
Mitigation
Ruckus has released a firmware update (200.7.10.102.64 or later) to address this issue [1]. Users should upgrade to the latest version. If patching is not possible, restrict network access to the management interface and disable WAN-facing services.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Ruckus Wireless/Unleasheddescription
- Range: <=200.7.10.102.64
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- alephsecurity.com/2020/01/14/ruckus-wirelessmitrex_refsource_MISC
- fahrplan.events.ccc.de/congress/2019/Fahrplan/events/10816.htmlmitrex_refsource_MISC
- www.ruckuswireless.com/security/299/view/txtmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.