Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2020-8830

Disclosure Date: May 05, 2020 (last updated February 21, 2025)
CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field on the Wireless Admin screen.
Attacker Value
Unknown

CVE-2020-8033

Disclosure Date: May 05, 2020 (last updated February 21, 2025)
Ruckus R500 3.4.2.0.384 devices allow XSS via the index.asp Device Name field.
Attacker Value
Unknown

CVE-2020-7983

Disclosure Date: May 05, 2020 (last updated February 21, 2025)
A CSRF issue in login.asp on Ruckus R500 3.4.2.0.384 devices allows remote attackers to access the panel or conduct SSRF attacks.
Attacker Value
Unknown

CVE-2020-8438

Disclosure Date: January 29, 2020 (last updated February 21, 2025)
Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hidden /forms/nslookupHandler form, as demonstrated by the nslookuptarget=|cat${IFS} substring.