Vulnerabilities > CVE-2020-26878 - Missing Authorization vulnerability in Commscope Ruckus Vriot 1.5.1.0.21
Attack vector
NETWORK Attack complexity
LOW Privileges required
SINGLE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoint), injecting arbitrary commands that will be executed as root user via web.py.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 | |
Hardware | 1 |