An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled input to the shell without adequate validation, enabling a remote attacker to specify a target by MAC address and execute arbitrary commands as root.
The diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled data directly to the system shell without proper input validation (CWE-77: command injection). An attacker with access to an administrator account can specify a target via MAC address and inject arbitrary system commands. These commands are executed in the context of the root account, providing full control over the device.
An attacker can execute arbitrary commands with root privileges on the vulnerable device, leading to complete device compromise, loss of confidentiality, integrity and system availability, and potential lateral movement within the network.
Update Ruckus Unleashed software to version 200.15.6.212.14 or later (for the 200.15 branch) or to version 200.17.7.0.139 or later (for the 200.17 branch). Detailed information is available in the vendor's security bulletin: https://support.ruckuswireless.com/security_bulletins/330. Until the patch is deployed, it is recommended to restrict access to the device administrative interface only to trusted hosts and management networks.
CommScope Ruckus Unleashed in versions prior to 200.15.6.212.14 and 200.17.7.0.139, installed on devices: Ruckus M510-JP, Ruckus T350C, Ruckus R350, Ruckus E510, Ruckus T811-CM.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HCommscope Ruckus C110
HWCommscopeall versionsCommscope Ruckus E510
HWCommscopeall versionsCommscope Ruckus H320
HWCommscopeall versionsCommscope Ruckus H350
HWCommscopeall versionsCommscope Ruckus H510
HWCommscopeall versionsCommscope Ruckus H550
HWCommscopeall versionsCommscope Ruckus M510
HWCommscopeall versionsCommscope Ruckus M510 Jp
HWCommscopeall versionsCommscope Ruckus R310
HWCommscopeall versionsCommscope Ruckus R320
HWCommscopeall versionsCommscope Ruckus R350
HWCommscopeall versionsCommscope Ruckus R350e
HWCommscopeall versionsCommscope Ruckus R510
HWCommscopeall versionsCommscope Ruckus R550
HWCommscopeall versionsCommscope Ruckus R560
HWCommscopeall versionsCommscope Ruckus R610
HWCommscopeall versionsCommscope Ruckus R650
HWCommscopeall versionsCommscope Ruckus R670
HWCommscopeall versionsCommscope Ruckus R710
HWCommscopeall versionsCommscope Ruckus R720
HWCommscopeall versionsCommscope Ruckus R730
HWCommscopeall versionsCommscope Ruckus R750
HWCommscopeall versionsCommscope Ruckus R760
HWCommscopeall versionsCommscope Ruckus R770
HWCommscopeall versionsCommscope Ruckus R850
HWCommscopeall versionsCommscope Ruckus T310c
HWCommscopeall versionsCommscope Ruckus T310n
HWCommscopeall versionsCommscope Ruckus T310s
HWCommscopeall versionsCommscope Ruckus T350c
HWCommscopeall versionsCommscope Ruckus T350d
HWCommscopeall versions
Related vulnerabilities
Hardcoded SSH private key w RUCKUS SmartZone — dostęp root zdalnie
Command injection w RUCKUS SmartZone przez pole adresu IP
Path traversal w Ruckus Unleashed/ZoneDirector umożliwia RCE bez uwierzytelnienia
Command injection w CommScope Ruckus — wykonanie komend jako root przez CLI
Format string RCE w CommScope Ruckus Unleashed — nieuwierzytelniony dostęp