CVEs (9)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp. |
1Ruckuswireless 2Ruckus Unleashed Ruckus ZonedirectorJun 17, 2026 Jul 21, 2025 N/A· v4 7.2 HIGH· v3 N/A· v2 An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where the authenticated configuration endpoint `/admin/_conf.jsp` write...Show more |
1Ruckuswireless 2Ruckus Unleashed Ruckus ZonedirectorJun 17, 2026 Jul 21, 2025 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled input to the shell with...Show more |
1Ruckuswireless 2Ruckus Unleashed Ruckus ZonedirectorJun 17, 2026 Jul 21, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to...Show more |
1Ruckuswireless 2Ruckus Unleashed Ruckus ZonedirectorJun 17, 2026 Jul 21, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execut...Show more |
1Ruckuswireless 2Ruckus Unleashed Ruckus ZonedirectorJun 17, 2026 Jul 21, 2025 N/A· v4 6.3 MEDIUM· v3 N/A· v2 An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where an authenticated request to the management endpoint `/admin/_cmds...Show more |
1Ruckuswireless 2Ruckus Unleashed Ruckus ZonedirectorJun 17, 2026 Jul 21, 2025 N/A· v4 5.3 MEDIUM· v3 N/A· v2 An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access...Show more |
1Ruckuswireless 2Ruckus Unleashed Ruckus ZonedirectorJun 17, 2026 Jul 21, 2025 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where a hidden debug script `.ap_debug.sh` invoked from the restricted...Show more |
1Ruckuswireless 2Ruckus Unleashed Ruckus ZonedirectorJun 17, 2026 Jul 21, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the passphrase requirement...Show more |