📦

ruckus_c110

Vendor: commscope

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 5 Remote Access
Total CVEs 26 Total Indexed
Avg. EPSS 0.98% Exploit Prob.
Latest CVE CVE-2025-44962 Aug 04

Security Vulnerability Index

Page 2 / 3
5.3 CVSS

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remote attacker to upload or retrieve arbitrary files from writable firmware directories and thereby expose sensitive information or compromise the controller.

EPSS: 0.50%
9.1 CVSS

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where a hidden debug script `.ap_debug.sh` invoked from the restricted CLI does not properly sanitize its input, allowing an authenticated attacker to execute arbitrary commands as root on the controller or specified target.

EPSS: 0.81%
8.8 CVSS

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the passphrase requirement for a hidden CLI command `!v54!` via a management API call and then invoke it to escape the restricted shell and obtain a root shell on the controller.

EPSS: 0.49%