← Back

Commscope

commscope

54 CVEs • 96 products

Products (96)

Click to collapse
Toggle
Ruckus Vriot
ruckus_vriot
Arris Sbg901
arris_sbg901
Arris Tg1682g
arris_tg1682g
Arris Nvg589
arris_nvg589
Arris Nvg599
arris_nvg599
Arris Dg950a
arris_dg950a
Arris Dg950s
arris_dg950s
Tr4400
tr4400
Arris Tg1692a
arris_tg1692a
Arris Tr3300
arris_tr3300
Arris Tg2482a
arris_tg2482a
Arris Tg2492
arris_tg2492
Arris Sbg10
arris_sbg10
Dg3450
dg3450
Ruckus C110
ruckus_c110
Ruckus E510
ruckus_e510
Ruckus H320
ruckus_h320
Ruckus H350
ruckus_h350
Ruckus H510
ruckus_h510
Ruckus H550
ruckus_h550
Ruckus M510
ruckus_m510
Ruckus R310
ruckus_r310
Ruckus R320
ruckus_r320
Ruckus R350
ruckus_r350
Ruckus R350e
ruckus_r350e
Ruckus R510
ruckus_r510
Ruckus R550
ruckus_r550
Ruckus R560
ruckus_r560
Ruckus R610
ruckus_r610
Ruckus R650
ruckus_r650
Ruckus R670
ruckus_r670
Ruckus R710
ruckus_r710
Ruckus R720
ruckus_r720
Ruckus R730
ruckus_r730
Ruckus R750
ruckus_r750
Ruckus R760
ruckus_r760
Ruckus R770
ruckus_r770
Ruckus R850
ruckus_r850
Ruckus T310c
ruckus_t310c
Ruckus T310n
ruckus_t310n
Ruckus T310s
ruckus_t310s
Ruckus T350c
ruckus_t350c
Ruckus T350d
ruckus_t350d
Ruckus T350se
ruckus_t350se
Ruckus T610
ruckus_t610
Ruckus T670
ruckus_t670
Ruckus T710
ruckus_t710
Ruckus T710s
ruckus_t710s
Ruckus T750
ruckus_t750
Ruckus T750se
ruckus_t750se
Ruckus T310d
ruckus_t310d

CVEs (54)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Commscope
1Arris Tr3300 Firmware
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin parameter. This vulnerability allows attackers to execute arbitrary commands via a craf...Show more
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Commscope
1Arris Tr3300 Firmware
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the upnp function via the upnp_ttl parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
1Commscope
1Arris Tr3300 Firmware
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoe_username, pppoe_passwd, and pppoe_servicename parameters. This vulnerability allows attackers to execut...Show more
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoe_username, pppoe_passwd, and pppoe_servicename parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Commscope
1Arris Tr3300 Firmware
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pptp (wan_pptp.html) function via the pptp_fix_ip, pptp_fix_mask, pptp_fix_gw, and wan_dns1_stat parameters. This vulnerability allo...Show more
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pptp (wan_pptp.html) function via the pptp_fix_ip, pptp_fix_mask, pptp_fix_gw, and wan_dns1_stat parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Commscope
5Arris Surfboard Sbg10 Firmware
Arris Surfboard Sbg6950ac2 FirmwareArris Surfboard Sbg7400ac2 Firmware+2 more
Jun 17, 2026
Feb 15, 2022
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
CommScope SURFboard SBG6950AC2 9.1.103AA23 devices allow Command Injection.
1Commscope
1Arris Surfboard Sb8200 Firmware
Jun 17, 2026
Nov 9, 2021
N/A· v4
7.1 HIGH· v3
4.9 MEDIUM· v2
The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in user to change the administrator password.
1Commscope
1Arris Surfboard Sb8200 Firmware
Jun 17, 2026
Oct 21, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an attacker could make configuration changes (such as changing the adminis...Show more
The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an attacker could make configuration changes (such as changing the administrative password) without the consent of the user.Show less
1Commscope
1Ruckus Iot Controller
Jun 17, 2026
Jul 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints.
1Commscope
1Ruckus Iot Controller
Jun 17, 2026
Jul 7, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. Hard-coded API Keys exist.
1Commscope
1Ruckus Iot Controller
Jun 17, 2026
Jul 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded Web Application Administrator Passwords for the admin and nplus1user accounts.
1Commscope
1Ruckus Iot Controller
Jun 17, 2026
Jul 7, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded System Passwords that provide shell access.
1Commscope
1Ruckus Iot Controller
Jun 17, 2026
Jul 7, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The Web Application allows Arbitrary Read/Write actions by authenticated users. The API allows an HTTP POST of arbitrary content into any fi...Show more
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The Web Application allows Arbitrary Read/Write actions by authenticated users. The API allows an HTTP POST of arbitrary content into any file on the filesystem as root.Show less
1Commscope
1Ruckus Iot Controller
Jun 17, 2026
Jul 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a developer account.
1Commscope
1Ruckus Iot Controller
Jun 17, 2026
Jul 7, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The API allows Directory Traversal.
1Commscope
1Ruckus Vriot
Jun 17, 2026
Oct 26, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the service API by using a backdoor value as the Authorization header.
1Commscope
1Ruckus Vriot
Jun 17, 2026
Oct 26, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoint), injecting arbitrary commands that will be executed as root user vi...Show more
Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoint), injecting arbitrary commands that will be executed as root user via web.py.Show less
1Commscope
1Ruckus Zoneflex R500 Firmware
Jun 17, 2026
May 5, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field on the Wireless Admin screen.
1Commscope
1Ruckus Zoneflex R500 Firmware
Jun 17, 2026
May 5, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Ruckus R500 3.4.2.0.384 devices allow XSS via the index.asp Device Name field.
1Commscope
1Ruckus Zoneflex R500 Firmware
Jun 17, 2026
May 5, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
A CSRF issue in login.asp on Ruckus R500 3.4.2.0.384 devices allows remote attackers to access the panel or conduct SSRF attacks.
1Commscope
1Arris Tg1692a Firmware
Jun 17, 2026
Mar 4, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ARRIS TG1692A devices allow remote attackers to discover the administrator login name and password by reading the /login page and performing base64 decoding.