VYPR

Wireless Admin

by Ruckus

CVEs (2)

  • CVE-2023-25717CriKEVFeb 13, 2023
    risk 0.83cvss 9.8epss 0.98

    Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring.

  • CVE-2020-8830HigMay 5, 2020
    risk 0.57cvss 8.8epss 0.01

    CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field on the Wireless Admin screen.