An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where a hidden debug script `.ap_debug.sh` invoked from the restricted CLI does not properly sanitize its input, allowing an authenticated attacker to execute arbitrary commands as root on the controller or specified target.
The command injection vulnerability (CWE-78) consists of the hidden debugging script `.ap_debug.sh`, available from the restricted CLI level, not applying proper sanitization of input data. An attacker with access to an administrative account can inject arbitrary system commands as arguments to this script. The executed commands are run in the root account context — both on the controller itself and on the remotely specified target device. The network vector (AV:N) means that the attack can be conducted remotely over the network.
The attacker gains full control over the controller or target network device with root privileges, enabling data theft, configuration modification, malicious software installation, and further lateral movement within the network infrastructure.
The software should be updated to Ruckus Unleashed version 200.15.6.212.14 or 200.17.7.0.139 or later, and Ruckus ZoneDirector to version 10.5.1.0.279 or later. Detailed instructions are available in the vendor's security bulletin: https://support.ruckuswireless.com/security_bulletins/330. As a temporary measure, CLI access should be restricted exclusively to trusted, authorized administrative networks.
CommScope Ruckus Unleashed in versions prior to 200.15.6.212.14 and 200.17.7.0.139, as well as Ruckus ZoneDirector in versions prior to 10.5.1.0.279. Vulnerable devices include: Ruckus M510-JP, T350C, R350, E510, T811-CM.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HCommscope Ruckus C110
HWCommscopeall versionsCommscope Ruckus E510
HWCommscopeall versionsCommscope Ruckus H320
HWCommscopeall versionsCommscope Ruckus H350
HWCommscopeall versionsCommscope Ruckus H510
HWCommscopeall versionsCommscope Ruckus H550
HWCommscopeall versionsCommscope Ruckus M510
HWCommscopeall versionsCommscope Ruckus M510 Jp
HWCommscopeall versionsCommscope Ruckus R310
HWCommscopeall versionsCommscope Ruckus R320
HWCommscopeall versionsCommscope Ruckus R350
HWCommscopeall versionsCommscope Ruckus R350e
HWCommscopeall versionsCommscope Ruckus R510
HWCommscopeall versionsCommscope Ruckus R550
HWCommscopeall versionsCommscope Ruckus R560
HWCommscopeall versionsCommscope Ruckus R610
HWCommscopeall versionsCommscope Ruckus R650
HWCommscopeall versionsCommscope Ruckus R670
HWCommscopeall versionsCommscope Ruckus R710
HWCommscopeall versionsCommscope Ruckus R720
HWCommscopeall versionsCommscope Ruckus R730
HWCommscopeall versionsCommscope Ruckus R750
HWCommscopeall versionsCommscope Ruckus R760
HWCommscopeall versionsCommscope Ruckus R770
HWCommscopeall versionsCommscope Ruckus R850
HWCommscopeall versionsCommscope Ruckus T310c
HWCommscopeall versionsCommscope Ruckus T310n
HWCommscopeall versionsCommscope Ruckus T310s
HWCommscopeall versionsCommscope Ruckus T350c
HWCommscopeall versionsCommscope Ruckus T350d
HWCommscopeall versions
Related vulnerabilities
Hardcoded SSH private key w RUCKUS SmartZone — dostęp root zdalnie
Command injection w RUCKUS SmartZone przez pole adresu IP
Format string RCE w CommScope Ruckus Unleashed — nieuwierzytelniony dostęp
Path traversal w Ruckus Unleashed/ZoneDirector umożliwia RCE bez uwierzytelnienia
Command injection w Ruckus Unleashed — zdalne wykonanie poleceń jako root