VYPR

Vendor CVEs

Commscope

All CVEs

62 total · sorted by risk
  • CVE-2017-16836MedNov 16, 2017
    risk 0.43cvss 6.1epss 0.02

    Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via the actionHandler/ajax_managed_services.php service parameter.

  • CVE-2017-9476MedJul 31, 2017
    risk 0.42cvss 6.5epss 0.02

    The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST); and Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version…

  • CVE-2025-46119MedJul 21, 2025
    risk 0.41cvss 6.3epss 0.00

    An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where an authenticated request to the management endpoint `/admin/_cmdstat.jsp` discloses the administrator password in a…

  • CVE-2023-27572MedApr 15, 2023
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in CommScope Arris DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. A reflected XSS vulnerability was discovered in the https_redirect.php web page via the page parameter.

  • CVE-2020-8033MedMay 5, 2020
    risk 0.40cvss 6.1epss 0.01

    Ruckus R500 3.4.2.0.384 devices allow XSS via the index.asp Device Name field.

  • CVE-2023-27571MedApr 15, 2023
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. The troubleshooting_logs_download.php log file download functionality does not check the session cookie. Thus, an attacker can download all log files.

  • CVE-2017-9491MedJul 31, 2017
    risk 0.35cvss 5.3epss 0.01

    The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST); Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST); Cisco DPC3941T (firmware…

  • CVE-2025-44958MedAug 4, 2025
    risk 0.34cvss 5.3epss 0.00

    RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format.

  • CVE-2025-46118MedJul 21, 2025
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remote attacker to upload or…

  • CVE-2025-44962MedAug 4, 2025
    risk 0.33cvss 5.0epss 0.01

    RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files.

  • CVE-2021-33215MedJul 7, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The API allows Directory Traversal.

  • CVE-2014-3778Jun 19, 2014
    risk 0.03cvss epss 0.02

    Multiple cross-site request forgery (CSRF) vulnerabilities in goform/RgDdns in ARRIS (formerly Motorola) SBG901 SURFboard Wireless Cable Modem allow remote attackers to hijack the authentication of administrators for requests that (1) change the dns service via the DdnsService…

Page 2 of 2