VYPR

Vendor CVEs

Ruckus

All CVEs

73 total · sorted by risk
  • CVE-2020-13915HigJul 28, 2020
    risk 0.49cvss 7.5epss 0.02

    Insecure permissions in emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allow a remote attacker to overwrite admin credentials via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720,…

  • CVE-2020-13914HigJul 28, 2020
    risk 0.49cvss 7.5epss 0.02

    webs in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to cause a denial of service (Segmentation fault) to the webserver via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710,…

  • CVE-2019-19835HigJan 23, 2020
    risk 0.49cvss 7.5epss 0.02

    SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of service via the server attribute to the tools/_rcmdstat.jsp URI.

  • CVE-2016-1000215HigOct 25, 2016
    risk 0.49cvss 7.5epss 0.01

    Ruckus Wireless H500 web management interface denial of service

  • CVE-2025-46123HigJul 21, 2025
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where the authenticated configuration endpoint `/admin/_conf.jsp` writes the Wi-Fi guest password to memory with snprintf using…

  • CVE-2020-8438HigJan 29, 2020
    risk 0.47cvss 7.2epss 0.02

    Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hidden /forms/nslookupHandler form, as demonstrated by the nslookuptarget=|cat${IFS} substring.

  • CVE-2019-19834HigJan 22, 2020
    risk 0.47cvss 7.2epss 0.02

    Directory Traversal in ruckus_cli2 in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote attacker to jailbreak the CLI via enable->debug->script->exec with ../../../bin/sh as the parameter.

  • CVE-2020-22661MedJan 20, 2023
    risk 0.42cvss 6.5epss 0.01

    In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300)…

  • CVE-2025-46119MedJul 21, 2025
    risk 0.41cvss 6.3epss 0.00

    An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where an authenticated request to the management endpoint `/admin/_cmdstat.jsp` discloses the administrator password in a…

  • CVE-2025-63735MedNov 25, 2025
    risk 0.40cvss 6.1epss 0.00

    A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp.

  • CVE-2023-49225MedDec 7, 2023
    risk 0.40cvss 6.1epss 0.00

    A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector, SmartZone, and AP Solo). If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in the product. As for the affected…

  • CVE-2020-21161MedJun 27, 2022
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in Ruckus Wireless ZoneDirector 9.8.3.0.

  • CVE-2020-13913MedJul 28, 2020
    risk 0.40cvss 6.1epss 0.01

    An XSS issue in emfd in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to execute JavaScript code via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n,…

  • CVE-2020-8033MedMay 5, 2020
    risk 0.40cvss 6.1epss 0.01

    Ruckus R500 3.4.2.0.384 devices allow XSS via the index.asp Device Name field.

  • CVE-2018-11027MedMay 29, 2018
    risk 0.40cvss 6.1epss 0.01

    A reflected XSS vulnerability on Ruckus ICX7450-48 devices allows remote attackers to inject arbitrary web script or HTML.

  • CVE-2019-19837MedJan 23, 2020
    risk 0.35cvss 5.3epss 0.02

    Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote information disclosure of bin/web.conf via HTTP requests.

  • CVE-2016-1000214MedOct 25, 2016
    risk 0.35cvss 5.3epss 0.01

    Ruckus Wireless H500 web management interface authentication bypass

  • CVE-2025-44958MedAug 4, 2025
    risk 0.34cvss 5.3epss 0.00

    RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format.

  • CVE-2025-46118MedJul 21, 2025
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remote attacker to upload or…

  • CVE-2025-44962MedAug 4, 2025
    risk 0.33cvss 5.0epss 0.01

    RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files.

  • CVE-2021-4474MedMar 26, 2026
    risk 0.32cvss 4.9epss 0.00

    Ruckus Access Point products contain an arbitrary file read vulnerability in the command-line interface that allows authenticated remote attackers with administrative privileges to read arbitrary files from the underlying filesystem. Attackers can exploit this vulnerability to…

  • CVE-2020-7234MedJan 19, 2020
    risk 0.31cvss 4.8epss 0.01

    Ruckus ZoneFlex R310 104.0.0.0.1347 devices allow Stored XSS via the SSID field on the Configuration > Radio 2.4G > Wireless X screen (after a successful login to the super account).

  • CVE-2013-5030Oct 16, 2013
    risk 0.03cvss epss 0.02

    Ruckus Wireless Zoneflex 2942 devices with firmware 9.6.0.0.267 allow remote attackers to bypass authentication, and subsequently access certain configuration/ and maintenance/ scripts, by constructing a crafted URI after receiving an authentication error for an arbitrary login…

Page 2 of 2