← Back

Commscope

commscope

54 CVEs • 96 products

Products (96)

Click to collapse
Toggle
Ruckus Vriot
ruckus_vriot
Arris Sbg901
arris_sbg901
Arris Tg1682g
arris_tg1682g
Arris Nvg589
arris_nvg589
Arris Nvg599
arris_nvg599
Arris Dg950a
arris_dg950a
Arris Dg950s
arris_dg950s
Tr4400
tr4400
Arris Tg1692a
arris_tg1692a
Arris Tr3300
arris_tr3300
Arris Tg2482a
arris_tg2482a
Arris Tg2492
arris_tg2492
Arris Sbg10
arris_sbg10
Dg3450
dg3450
Ruckus C110
ruckus_c110
Ruckus E510
ruckus_e510
Ruckus H320
ruckus_h320
Ruckus H350
ruckus_h350
Ruckus H510
ruckus_h510
Ruckus H550
ruckus_h550
Ruckus M510
ruckus_m510
Ruckus R310
ruckus_r310
Ruckus R320
ruckus_r320
Ruckus R350
ruckus_r350
Ruckus R350e
ruckus_r350e
Ruckus R510
ruckus_r510
Ruckus R550
ruckus_r550
Ruckus R560
ruckus_r560
Ruckus R610
ruckus_r610
Ruckus R650
ruckus_r650
Ruckus R670
ruckus_r670
Ruckus R710
ruckus_r710
Ruckus R720
ruckus_r720
Ruckus R730
ruckus_r730
Ruckus R750
ruckus_r750
Ruckus R760
ruckus_r760
Ruckus R770
ruckus_r770
Ruckus R850
ruckus_r850
Ruckus T310c
ruckus_t310c
Ruckus T310n
ruckus_t310n
Ruckus T310s
ruckus_t310s
Ruckus T350c
ruckus_t350c
Ruckus T350d
ruckus_t350d
Ruckus T350se
ruckus_t350se
Ruckus T610
ruckus_t610
Ruckus T670
ruckus_t670
Ruckus T710
ruckus_t710
Ruckus T710s
ruckus_t710s
Ruckus T750
ruckus_t750
Ruckus T750se
ruckus_t750se
Ruckus T310d
ruckus_t310d

CVEs (54)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Commscope
1Ruckus Network Director
Jun 17, 2026
Feb 19, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These keys are identical across all deployments, allowing an attacker with network access to authenticate...Show more
In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These keys are identical across all deployments, allowing an attacker with network access to authenticate via SSH without a password. Once authenticated, the attacker can access the PostgreSQL database with superuser privileges, create administrative users for the web interface, and potentially escalate privileges further.Show less
1Commscope
1Ruckus Network Director
Jun 17, 2026
Feb 19, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default configuration, the PostgreSQL service is accessible over the network o...Show more
In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default configuration, the PostgreSQL service is accessible over the network on TCP port 5432. An attacker can use the hardcoded credentials to authenticate remotely, gaining superuser access to the database. This allows creation of administrative users for the web interface, extraction of password hashes, and execution of arbitrary OS commands.Show less
1Commscope
1Ruckus Network Director
Jun 17, 2026
Aug 4, 2025
N/A· v4
8.1 HIGH· v3
N/A· v2
RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.
1Commscope
2Ruckus Network Director
Ruckus Smartzone Firmware
Jun 17, 2026
Aug 4, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files.
1Commscope
2Ruckus Network Director
Ruckus Smartzone Firmware
Jun 17, 2026
Aug 4, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.
1Commscope
2Ruckus Network Director
Ruckus Smartzone Firmware
Jun 17, 2026
Aug 4, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.
1Commscope
1Ruckus Network Director
Jun 17, 2026
Aug 4, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format.
1Commscope
2Ruckus Network Director
Ruckus Smartzone Firmware
Jun 17, 2026
Aug 4, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers.
1Commscope
1Ruckus Smartzone Firmware
Jun 17, 2026
Aug 4, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.
1Commscope
1Ruckus Network Director
Jun 17, 2026
Aug 4, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password.
1Commscope
1Arris Surfboard Sbg6950ac2 Firmware
Jun 17, 2026
Jan 26, 2024
N/A· v4
9.8 CRITICAL· v3
8.3 HIGH· v2
An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can exploit this vulnerability to achieve code execution as root.
1Commscope
1Ruckus Cloudpath Enrollment System
Jul 9, 2026
Oct 19, 2023
N/A· v4
9.6 CRITICAL· v3
N/A· v2
A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user...Show more
A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user of the admin management interface. A successful attack, combined with a certain admin activity, could allow the attacker to gain full admin privileges on the exploited system.Show less
1Commscope
1Dg3450 Firmware
Jun 17, 2026
Apr 15, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in CommScope Arris DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. A reflected XSS vulnerability was discovered in the https_redirect.php web page via the page parameter.
1Commscope
1Dg3450 Firmware
Jun 17, 2026
Apr 15, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. The troubleshooting_logs_download.php log file download functionality does not check the session cookie. Thus, an attacker can download al...Show more
An issue was discovered in DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. The troubleshooting_logs_download.php log file download functionality does not check the session cookie. Thus, an attacker can download all log files.Show less
1Commscope
3Arris Sbg10 Firmware
Arris Tg2482a FirmwareArris Tg2492 Firmware
Jul 9, 2026
Feb 17, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
2Commscope
Ruckuswireless
3Ruckus Smartzone Firmware
Ruckus Wireless AdminSmartzone Ap
Jun 17, 2026
Feb 13, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring.
1Commscope
1Arris Tr3300 Firmware
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、ddns_host parameters. This vulnerability allows attackers to execute arbitrary co...Show more
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、ddns_host parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Commscope
1Arris Tr3300 Firmware
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
1Commscope
1Arris Tr3300 Firmware
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_server, h_backup_ntp_server, and h_time_zone parameters. This vulnerability allows...Show more
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_server, h_backup_ntp_server, and h_time_zone parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Commscope
1Arris Tr3300 Firmware
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wan_mask_stat, wan_gw_stat, and wan_dns1_stat parameters. This vulnerability allows...Show more
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wan_mask_stat, wan_gw_stat, and wan_dns1_stat parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less