An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to snprintf as the format string. A remote attacker can exploit this flaw either by sending a crafted request to the authenticated endpoint `/admin/_conf.jsp`, or without authentication and without direct network access to the controller by spoofing the MAC address of a favourite station and embedding malicious format specifiers in the DHCP hostname field, resulting in unauthenticated format-string processing and arbitrary code execution on the controller.
The functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass the client's hostname directly to `snprintf` as a format string instead of as an argument. An attacker can exploit this vulnerability in two ways: by sending a crafted request to the authenticated endpoint `/admin/_conf.jsp`, or — without authentication and without direct access to the controller — by spoofing the MAC address of a station on the favorites list and placing malicious format specifiers in the DHCP hostname field. In the second scenario, the controller processes the malicious format string without any authentication, leading to arbitrary code execution.
An attacker can gain full control over the controller, which includes violation of confidentiality, integrity, and system availability — including potential takeover of the entire wireless infrastructure managed by the controller.
Update Ruckus Unleashed software to version 200.15.6.212.14 or 200.17.7.0.139 (or newer). Detailed information is available in the vendor's security bulletin at https://support.ruckuswireless.com/security_bulletins/330. Until the patch is implemented, it is recommended to restrict access to the controller's administrative interface and monitor anomalies in DHCP traffic.
CommScope Ruckus Unleashed versions prior to 200.15.6.212.14 and 200.17.7.0.139, on devices: Ruckus M510-JP, Ruckus T350C, Ruckus R350, Ruckus E510, Ruckus T811-CM.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCommscope Ruckus C110
HWCommscopeall versionsCommscope Ruckus E510
HWCommscopeall versionsCommscope Ruckus H320
HWCommscopeall versionsCommscope Ruckus H350
HWCommscopeall versionsCommscope Ruckus H510
HWCommscopeall versionsCommscope Ruckus H550
HWCommscopeall versionsCommscope Ruckus M510
HWCommscopeall versionsCommscope Ruckus M510 Jp
HWCommscopeall versionsCommscope Ruckus R310
HWCommscopeall versionsCommscope Ruckus R320
HWCommscopeall versionsCommscope Ruckus R350
HWCommscopeall versionsCommscope Ruckus R350e
HWCommscopeall versionsCommscope Ruckus R510
HWCommscopeall versionsCommscope Ruckus R550
HWCommscopeall versionsCommscope Ruckus R560
HWCommscopeall versionsCommscope Ruckus R610
HWCommscopeall versionsCommscope Ruckus R650
HWCommscopeall versionsCommscope Ruckus R670
HWCommscopeall versionsCommscope Ruckus R710
HWCommscopeall versionsCommscope Ruckus R720
HWCommscopeall versionsCommscope Ruckus R730
HWCommscopeall versionsCommscope Ruckus R750
HWCommscopeall versionsCommscope Ruckus R760
HWCommscopeall versionsCommscope Ruckus R770
HWCommscopeall versionsCommscope Ruckus R850
HWCommscopeall versionsCommscope Ruckus T310c
HWCommscopeall versionsCommscope Ruckus T310n
HWCommscopeall versionsCommscope Ruckus T310s
HWCommscopeall versionsCommscope Ruckus T350c
HWCommscopeall versionsCommscope Ruckus T350d
HWCommscopeall versions
Related vulnerabilities
Hardcoded SSH private key w RUCKUS SmartZone — dostęp root zdalnie
Command injection w RUCKUS SmartZone przez pole adresu IP
Path traversal w Ruckus Unleashed/ZoneDirector umożliwia RCE bez uwierzytelnienia
Command injection w CommScope Ruckus — wykonanie komend jako root przez CLI
Command injection w Ruckus Unleashed — zdalne wykonanie poleceń jako root