Vulnerability index

Browse CVEs

46 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-67305 In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These keys are identical across all… Ruckus Network Director 4.5.0.56+ Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2025-67304 In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default… Ruckus Network Director 4.5.0.56+ Fix from $2,3002026-02-19 HIGH 8.8 CVE-2025-44960 RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route. Ruckus Smartzone Firmware 4.5.0.51 / 6.1.2+ Fix from $1,9502025-08-04 HIGH 8.8 CVE-2025-44961 In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user. Ruckus Smartzone Firmware 4.5.0.51 / 6.1.2+ Fix from $1,9502025-08-04 HIGH 8.1 CVE-2025-44963 RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key. Ruckus Network Director 4.5.0.0+ Fix from $1,9502025-08-04 CRITICAL 9.8 CVE-2025-44954 RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account. Ruckus Smartzone Firmware 6.1.2+ Fix from $2,3002025-08-04 HIGH 8.8 CVE-2025-44957 Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers. Ruckus Smartzone Firmware 4.5.0.51 / 6.1.2+ Fix from $1,9502025-08-04 HIGH 7.5 CVE-2025-44958 RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format. Ruckus Network Director 4.5.0.0+ Fix from $1,9502025-08-04 HIGH 8.8 CVE-2025-44955 RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password. Ruckus Network Director 4.5.0.0+ Fix from $1,9502025-08-04 CRITICAL 9.8 CVE-2024-23618 An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can exploit this vulnerability to… Arris Surfboard Sbg6950ac2 Firmware Mitigation only Fix from $2,3002024-01-26 CRITICAL 9.6 CVE-2023-45992 A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthentica… Ruckus Cloudpath Enrollment System after 5.12.5538 Fix from $2,3002023-10-19 MEDIUM 6.1 CVE-2023-27572 An issue was discovered in CommScope Arris DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. A reflected XSS vulnerability was discovered in the… Dg3450 Firmware No fix yet Fix from $1,6002023-04-15 MEDIUM 5.3 CVE-2023-27571 An issue was discovered in DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. The troubleshooting_logs_download.php log file download functionali… Dg3450 Firmware No fix yet Fix from $1,6002023-04-15 HIGH 8.8 CVE-2022-45701EPSS 42% Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature. Arris Tg2482a Firmware after 9.1.103 Fix from $1,9502023-02-17 CRITICAL 9.8 CVE-2022-26996 Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoe_username, pppoe_passwd, and pppo… Arris Tr3300 Firmware No fix yet Fix from $2,3002022-03-15 CRITICAL 9.8 CVE-2022-26997 Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the upnp function via the upnp_ttl parameter. This vulnerability … Arris Tr3300 Firmware No fix yet Fix from $2,3002022-03-15 CRITICAL 9.8 CVE-2022-26998 Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin parameter. This … Arris Tr3300 Firmware No fix yet Fix from $2,3002022-03-15 CRITICAL 9.8 CVE-2022-26999 Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wan_mask_sta… Arris Tr3300 Firmware No fix yet Fix from $2,3002022-03-15 CRITICAL 9.8 CVE-2022-27000 Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_server, h_b… Arris Tr3300 Firmware No fix yet Fix from $2,3002022-03-15 CRITICAL 9.8 CVE-2022-27001 Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter. This vulnerability… Arris Tr3300 Firmware No fix yet Fix from $2,3002022-03-15 CRITICAL 9.8 CVE-2022-27002EPSS 5% Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、ddns_host… Arris Tr3300 Firmware No fix yet Fix from $2,3002022-03-15 CRITICAL 9.8 CVE-2022-26995 Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pptp (wan_pptp.html) function via the pptp_fix_ip, pptp_fix_m… Arris Tr3300 Firmware No fix yet Fix from $2,3002022-03-15 HIGH 8.8 CVE-2021-41552 CommScope SURFboard SBG6950AC2 9.1.103AA23 devices allow Command Injection. Arris Surfboard Sbg6950ac2 Firmware Mitigation only Fix from $1,9502022-02-15 HIGH 7.1 CVE-2021-20119 The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in user to change the administrato… Arris Surfboard Sb8200 Firmware No fix yet Fix from $1,9502021-11-09 HIGH 8.8 CVE-2021-20120 The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an … Arris Surfboard Sb8200 Firmware No fix yet Fix from $1,9502021-10-21 CRITICAL 9.8 CVE-2021-33218 An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded System Passwords that provide shell access. Ruckus Iot Controller after 1.7.1.0 Fix from $2,3002021-07-07 CRITICAL 9.8 CVE-2021-33219 An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded Web Application Administrator Passwords for the … Ruckus Iot Controller after 1.7.1.0 Fix from $2,3002021-07-07 CRITICAL 9.8 CVE-2021-33221EPSS 56% An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints. Ruckus Iot Controller after 1.7.1.0 Fix from $2,3002021-07-07 HIGH 8.8 CVE-2021-33217 An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The Web Application allows Arbitrary Read/Write actions by authentica… Ruckus Iot Controller after 1.7.1.0 Fix from $1,9502021-07-07 HIGH 7.8 CVE-2021-33220 An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. Hard-coded API Keys exist. Ruckus Iot Controller after 1.7.1.0 Fix from $1,9502021-07-07