VYPR

Ruckus Zoneflex R500 Firmware

by Commscope

CVEs (3)

  • CVE-2020-8830HigMay 5, 2020
    risk 0.57cvss 8.8epss 0.01

    CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field on the Wireless Admin screen.

  • CVE-2020-7983HigMay 5, 2020
    risk 0.53cvss 8.1epss 0.01

    A CSRF issue in login.asp on Ruckus R500 3.4.2.0.384 devices allows remote attackers to access the panel or conduct SSRF attacks.

  • CVE-2020-8033MedMay 5, 2020
    risk 0.40cvss 6.1epss 0.01

    Ruckus R500 3.4.2.0.384 devices allow XSS via the index.asp Device Name field.