Commscope
commscope
54 CVEs • 96 products
Products (96)
Click to collapseToggle
Products (96)
Click to collapse
CVEs (54)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Commscope 1Ruckus Network Director Jun 17, 2026 Feb 19, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These keys are identical across all deployments, allowing an attacker with network access to authenticate...Show more |
1Commscope 1Ruckus Network Director Jun 17, 2026 Feb 19, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default configuration, the PostgreSQL service is accessible over the network o...Show more |
RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key. |
1Commscope 2Ruckus Network Director Ruckus Smartzone FirmwareJun 17, 2026 Aug 4, 2025 N/A· v4 4.3 MEDIUM· v3 N/A· v2 RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files. |
1Commscope 2Ruckus Network Director Ruckus Smartzone FirmwareJun 17, 2026 Aug 4, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user. |
1Commscope 2Ruckus Network Director Ruckus Smartzone FirmwareJun 17, 2026 Aug 4, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route. |
RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format. |
1Commscope 2Ruckus Network Director Ruckus Smartzone FirmwareJun 17, 2026 Aug 4, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers. |
1Commscope 1Ruckus Smartzone Firmware Jun 17, 2026 Aug 4, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account. |
RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password. |
1Commscope 1Arris Surfboard Sbg6950ac2 Firmware Jun 17, 2026 Jan 26, 2024 N/A· v4 9.8 CRITICAL· v3 8.3 HIGH· v2 An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can exploit this vulnerability to achieve code execution as root.
|
1Commscope 1Ruckus Cloudpath Enrollment System Jul 9, 2026 Oct 19, 2023 N/A· v4 9.6 CRITICAL· v3 N/A· v2 A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user...Show more |
An issue was discovered in CommScope Arris DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. A reflected XSS vulnerability was discovered in the https_redirect.php web page via the page parameter. |
An issue was discovered in DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. The troubleshooting_logs_download.php log file download functionality does not check the session cookie. Thus, an attacker can download al...Show more |
1Commscope 3Arris Sbg10 Firmware Arris Tg2482a FirmwareArris Tg2492 FirmwareJul 9, 2026 Feb 17, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature. |
2Commscope Ruckuswireless3Ruckus Smartzone Firmware Ruckus Wireless AdminSmartzone ApJun 17, 2026 Feb 13, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring. |
1Commscope 1Arris Tr3300 Firmware Jun 17, 2026 Mar 15, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、ddns_host parameters. This vulnerability allows attackers to execute arbitrary co...Show more |
1Commscope 1Arris Tr3300 Firmware Jun 17, 2026 Mar 15, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. |
1Commscope 1Arris Tr3300 Firmware Jun 17, 2026 Mar 15, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_server, h_backup_ntp_server, and h_time_zone parameters. This vulnerability allows...Show more |
1Commscope 1Arris Tr3300 Firmware Jun 17, 2026 Mar 15, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wan_mask_stat, wan_gw_stat, and wan_dns1_stat parameters. This vulnerability allows...Show more |