Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jr2r-3x4h-x86g

Опубликовано: 21 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remote attacker to upload or retrieve arbitrary files from writable firmware directories and thereby expose sensitive information or compromise the controller.

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remote attacker to upload or retrieve arbitrary files from writable firmware directories and thereby expose sensitive information or compromise the controller.

EPSS

Процентиль: 21%
0.00067
Низкий

7.3 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 5.3
nvd
7 месяцев назад

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remote attacker to upload or retrieve arbitrary files from writable firmware directories and thereby expose sensitive information or compromise the controller.

EPSS

Процентиль: 21%
0.00067
Низкий

7.3 High

CVSS3

Дефекты

CWE-284