An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates outside permitted directories, allowing a remote unauthenticated attacker who can upload a template (e.g., via FTP) to escalate privileges and run arbitrary template code on the controller.
The web server processes EJS (Embedded JavaScript) templates without proper path validation, allowing references to files outside permitted directories (path traversal, CWE-22). An attacker who is able to upload a malicious EJS template to the device — for example via FTP protocol — can cause the server to execute this template outside the allowed area of the file system. The result is privilege escalation and execution of arbitrary template code in the context of the controller.
A remote, unauthenticated attacker can gain full control over the wireless network controller, escalate privileges, and execute arbitrary code, which may result in compromise of confidentiality, integrity, and availability of the entire infrastructure.
Update Ruckus Unleashed software to version at least 200.15.6.212.27 or 200.18.7.1.323, and ZoneDirector to version at least 10.5.1.0.282. It is also recommended to restrict access to the web interface and FTP service to trusted hosts and management networks only. Detailed information is available in the vendor security bulletin: https://support.ruckuswireless.com/security_bulletins/330
CommScope Ruckus Unleashed in versions prior to 200.15.6.212.27 and 200.18.7.1.323; CommScope Ruckus ZoneDirector in versions prior to 10.5.1.0.282. Listed hardware products: Ruckus M510-Jp, T350C, R350, E510, T811-Cm.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCommscope Ruckus C110
HWCommscopeall versionsCommscope Ruckus E510
HWCommscopeall versionsCommscope Ruckus H320
HWCommscopeall versionsCommscope Ruckus H350
HWCommscopeall versionsCommscope Ruckus H510
HWCommscopeall versionsCommscope Ruckus H550
HWCommscopeall versionsCommscope Ruckus M510
HWCommscopeall versionsCommscope Ruckus M510 Jp
HWCommscopeall versionsCommscope Ruckus R310
HWCommscopeall versionsCommscope Ruckus R320
HWCommscopeall versionsCommscope Ruckus R350
HWCommscopeall versionsCommscope Ruckus R350e
HWCommscopeall versionsCommscope Ruckus R510
HWCommscopeall versionsCommscope Ruckus R550
HWCommscopeall versionsCommscope Ruckus R560
HWCommscopeall versionsCommscope Ruckus R610
HWCommscopeall versionsCommscope Ruckus R650
HWCommscopeall versionsCommscope Ruckus R670
HWCommscopeall versionsCommscope Ruckus R710
HWCommscopeall versionsCommscope Ruckus R720
HWCommscopeall versionsCommscope Ruckus R730
HWCommscopeall versionsCommscope Ruckus R750
HWCommscopeall versionsCommscope Ruckus R760
HWCommscopeall versionsCommscope Ruckus R770
HWCommscopeall versionsCommscope Ruckus R850
HWCommscopeall versionsCommscope Ruckus T310c
HWCommscopeall versionsCommscope Ruckus T310n
HWCommscopeall versionsCommscope Ruckus T310s
HWCommscopeall versionsCommscope Ruckus T350c
HWCommscopeall versionsCommscope Ruckus T350d
HWCommscopeall versions
Related vulnerabilities
Hardcoded SSH private key w RUCKUS SmartZone — dostęp root zdalnie
Command injection w RUCKUS SmartZone przez pole adresu IP
Format string RCE w CommScope Ruckus Unleashed — nieuwierzytelniony dostęp
Command injection w CommScope Ruckus — wykonanie komend jako root przez CLI
Command injection w Ruckus Unleashed — zdalne wykonanie poleceń jako root