Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rv79-m662-c92x

Опубликовано: 21 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.12.304, where an authenticated request to the management endpoint /admin/_cmdstat.jsp discloses the administrator password in a trivially reversible obfuscated form. The same obfuscation method persists in configuration prior to 200.18.7.1.302, allowing anyone who obtains the system configuration to recover the plaintext credentials.

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.12.304, where an authenticated request to the management endpoint /admin/_cmdstat.jsp discloses the administrator password in a trivially reversible obfuscated form. The same obfuscation method persists in configuration prior to 200.18.7.1.302, allowing anyone who obtains the system configuration to recover the plaintext credentials.

EPSS

Процентиль: 17%
0.00052
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-555

Связанные уязвимости

CVSS3: 6.3
nvd
7 месяцев назад

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where an authenticated request to the management endpoint `/admin/_cmdstat.jsp` discloses the administrator password in a trivially reversible obfuscated form. The same obfuscation method persists in configuration prior to 200.18.7.1.302, allowing anyone who obtains the system configuration to recover the plaintext credentials.

EPSS

Процентиль: 17%
0.00052
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-555