← Back

CVE-2019-19836

nvd nist
Published: Jan 22, 2020Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote code execution via a POST request that uses tools/_rcmdstat.jsp to write to a specified filename.

Affected (7)

2 products
Unleashed
Zonedirector 1200 Firmware
Configuration A
1 vulnerable · 14 platform
Vulnerable SoftwareAffected Versions
Before 200.7.10.202.94
Running on/withPlatform Versions
Ruckuswireless
C110
All versions
Ruckuswireless
E510
All versions
Ruckuswireless
H320
All versions
Ruckuswireless
H510
All versions
Ruckuswireless
M510
All versions
Ruckuswireless
R310
All versions
Ruckuswireless
R320
All versions
Ruckuswireless
R510
All versions
Ruckuswireless
R610
All versions
Ruckuswireless
R710
All versions
Ruckuswireless
R720
All versions
Ruckuswireless
T310
All versions
Ruckuswireless
T610
All versions
Ruckuswireless
T710
All versions
Configuration B
6 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Ruckuswireless
Before 9.10.2.0.84
From 10.1.0 to 10.1.2.0.275
From 10.2.0 to 10.2.1.0.147
From 10.3.0 to 10.3.1.0.21
From 9.12.0 to 9.12.3.0.136
From 9.13.0 to 10.0.1.0.90
Running on/withPlatform Versions
Ruckuswireless
Zonedirector 1200
All versions

References (6)

Source: cve@mitre.org
ExploitTechnical DescriptionThird Party Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.