VYPR

Ruckus Iot Controller

by Commscope

CVEs (7)

  • CVE-2021-33221CriJul 7, 2021
    risk 0.68cvss 9.8epss 0.56

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints.

  • CVE-2021-33216CriJul 7, 2021
    risk 0.68cvss 9.8epss 0.14

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a developer account.

  • CVE-2021-33219CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded Web Application Administrator Passwords for the admin and nplus1user accounts.

  • CVE-2021-33218CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded System Passwords that provide shell access.

  • CVE-2021-33217HigJul 7, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The Web Application allows Arbitrary Read/Write actions by authenticated users. The API allows an HTTP POST of arbitrary content into any file on the filesystem as root.

  • CVE-2021-33220HigJul 7, 2021
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. Hard-coded API Keys exist.

  • CVE-2021-33215MedJul 7, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The API allows Directory Traversal.