Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2021-33219

Disclosure Date: July 07, 2021 (last updated February 23, 2025)
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded Web Application Administrator Passwords for the admin and nplus1user accounts.
Attacker Value
Unknown

CVE-2021-33216

Disclosure Date: July 07, 2021 (last updated February 23, 2025)
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a developer account.
Attacker Value
Unknown

CVE-2021-33215

Disclosure Date: July 07, 2021 (last updated February 23, 2025)
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The API allows Directory Traversal.
Attacker Value
Unknown

CVE-2021-33217

Disclosure Date: July 07, 2021 (last updated February 23, 2025)
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The Web Application allows Arbitrary Read/Write actions by authenticated users. The API allows an HTTP POST of arbitrary content into any file on the filesystem as root.
Attacker Value
Unknown

CVE-2021-33220

Disclosure Date: July 07, 2021 (last updated February 23, 2025)
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. Hard-coded API Keys exist.
Attacker Value
Unknown

CVE-2021-33218

Disclosure Date: July 07, 2021 (last updated February 23, 2025)
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded System Passwords that provide shell access.
Attacker Value
Unknown

CVE-2021-33221

Disclosure Date: July 07, 2021 (last updated February 23, 2025)
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints.