Vulnerability index

Browse CVEs

46 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ruckus Network Director CRITICAL 9.8
CVE-2025-67305

In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These keys are identical across all…

Fix: 4.5.0.56+
Fix from $2,300 2026-02-19
Ruckus Network Director CRITICAL 9.8
CVE-2025-67304

In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default…

Fix: 4.5.0.56+
Fix from $2,300 2026-02-19
Ruckus Smartzone Firmware HIGH 8.8
CVE-2025-44960

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.

Fix: 4.5.0.51 / 6.1.2+
Fix from $1,950 2025-08-04
Ruckus Smartzone Firmware HIGH 8.8
CVE-2025-44961

In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.

Fix: 4.5.0.51 / 6.1.2+
Fix from $1,950 2025-08-04
Ruckus Network Director HIGH 8.1
CVE-2025-44963

RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.

Fix: 4.5.0.0+
Fix from $1,950 2025-08-04
Ruckus Smartzone Firmware CRITICAL 9.8
CVE-2025-44954

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.

Fix: 6.1.2+
Fix from $2,300 2025-08-04
Ruckus Smartzone Firmware HIGH 8.8
CVE-2025-44957

Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers.

Fix: 4.5.0.51 / 6.1.2+
Fix from $1,950 2025-08-04
Ruckus Network Director HIGH 7.5
CVE-2025-44958

RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format.

Fix: 4.5.0.0+
Fix from $1,950 2025-08-04
Ruckus Network Director HIGH 8.8
CVE-2025-44955

RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password.

Fix: 4.5.0.0+
Fix from $1,950 2025-08-04
Arris Surfboard Sbg6950ac2 Firmware CRITICAL 9.8
CVE-2024-23618

An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can exploit this vulnerability to…

Mitigation only
Fix from $2,300 2024-01-26
Ruckus Cloudpath Enrollment System CRITICAL 9.6
CVE-2023-45992

A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthentica…

Fix: after 5.12.5538
Fix from $2,300 2023-10-19
Dg3450 Firmware MEDIUM 6.1
CVE-2023-27572

An issue was discovered in CommScope Arris DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. A reflected XSS vulnerability was discovered in the…

No fix yet
Fix from $1,600 2023-04-15
Dg3450 Firmware MEDIUM 5.3
CVE-2023-27571

An issue was discovered in DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. The troubleshooting_logs_download.php log file download functionali…

No fix yet
Fix from $1,600 2023-04-15
Arris Tg2482a Firmware HIGH 8.8
CVE-2022-45701EPSS 42%

Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.

Fix: after 9.1.103
Fix from $1,950 2023-02-17
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-26996

Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoe_username, pppoe_passwd, and pppo…

No fix yet
Fix from $2,300 2022-03-15
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-26997

Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the upnp function via the upnp_ttl parameter. This vulnerability …

No fix yet
Fix from $2,300 2022-03-15
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-26998

Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin parameter. This …

No fix yet
Fix from $2,300 2022-03-15
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-26999

Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wan_mask_sta…

No fix yet
Fix from $2,300 2022-03-15
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-27000

Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_server, h_b…

No fix yet
Fix from $2,300 2022-03-15
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-27001

Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter. This vulnerability…

No fix yet
Fix from $2,300 2022-03-15
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-27002EPSS 5%

Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、ddns_host…

No fix yet
Fix from $2,300 2022-03-15
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-26995

Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pptp (wan_pptp.html) function via the pptp_fix_ip, pptp_fix_m…

No fix yet
Fix from $2,300 2022-03-15
Arris Surfboard Sbg6950ac2 Firmware HIGH 8.8
CVE-2021-41552

CommScope SURFboard SBG6950AC2 9.1.103AA23 devices allow Command Injection.

Mitigation only
Fix from $1,950 2022-02-15
Arris Surfboard Sb8200 Firmware HIGH 7.1
CVE-2021-20119

The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in user to change the administrato…

No fix yet
Fix from $1,950 2021-11-09
Arris Surfboard Sb8200 Firmware HIGH 8.8
CVE-2021-20120

The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an …

No fix yet
Fix from $1,950 2021-10-21
Ruckus Iot Controller CRITICAL 9.8
CVE-2021-33218

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded System Passwords that provide shell access.

Fix: after 1.7.1.0
Fix from $2,300 2021-07-07
Ruckus Iot Controller CRITICAL 9.8
CVE-2021-33219

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded Web Application Administrator Passwords for the …

Fix: after 1.7.1.0
Fix from $2,300 2021-07-07
Ruckus Iot Controller CRITICAL 9.8
CVE-2021-33221EPSS 56%

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints.

Fix: after 1.7.1.0
Fix from $2,300 2021-07-07
Ruckus Iot Controller HIGH 8.8
CVE-2021-33217

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The Web Application allows Arbitrary Read/Write actions by authentica…

Fix: after 1.7.1.0
Fix from $1,950 2021-07-07
Ruckus Iot Controller HIGH 7.8
CVE-2021-33220

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. Hard-coded API Keys exist.

Fix: after 1.7.1.0
Fix from $1,950 2021-07-07