|
223251
|
9.8 |
CRITICAL
Network
|
ruckuswireless
|
unleashed zonedirector_1200_firmware
|
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=import-category to admin/_cmdstat.jsp via the uploa…
|
CWE-78
OS Command
|
CVE-2019-19839
|
2024-11-21 13:35 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223252
|
9.8 |
CRITICAL
Network
|
ruckuswireless
|
unleashed zonedirector_1200_firmware
|
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=get-platform-depends to admin/_cmdstat.jsp via the …
|
CWE-78
OS Command
|
CVE-2019-19838
|
2024-11-21 13:35 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223253
|
5.3 |
MEDIUM
Network
|
ruckuswireless
|
unleashed zonedirector_1200_firmware
|
Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote information disclosure of bin/web.conf via HTTP requests.
|
NVD-CWE-noinfo
|
CVE-2019-19837
|
2024-11-21 13:35 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223254
|
7.5 |
HIGH
Network
|
ruckuswireless
|
unleashed zonedirector_1200_firmware
|
SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of service via the server attribute to the tools/_rcmdstat.jsp URI.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-19835
|
2024-11-21 13:35 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223255
|
9.8 |
CRITICAL
Network
|
ruckuswireless
|
unleashed zonedirector_1200_firmware
|
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=spectra-analysis to admin/_cmdstat.jsp via the mac …
|
CWE-78
OS Command
|
CVE-2019-19842
|
2024-11-21 13:35 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223256
|
9.8 |
CRITICAL
Network
|
ruckuswireless
|
unleashed zonedirector_1200_firmware
|
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=packet-capture to admin/_cmdstat.jsp via the mac at…
|
CWE-78
OS Command
|
CVE-2019-19841
|
2024-11-21 13:35 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223257
|
9.8 |
CRITICAL
Network
|
ruckuswireless
|
unleashed zonedirector_1200_firmware
|
A stack-based buffer overflow in zap_parse_args in zap.c in zap in Ruckus Unleashed through 200.7.10.102.64 allows remote code execution via an unauthenticated HTTP request.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-19840
|
2024-11-21 13:35 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223258
|
9.8 |
CRITICAL
Network
|
ruckuswireless
|
unleashed zonedirector_1200_firmware
|
Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credential fetch via an unauthenticated HTTP request involving a symlink with /tmp and…
|
CWE-552 CWE-522
Files or Directories Accessible to External Parties Insufficiently Protected Credentials
|
CVE-2019-19843
|
2024-11-21 13:35 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223259
|
9.8 |
CRITICAL
Network
|
ruckuswireless
|
unleashed zonedirector_1200_firmware
|
AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote code execution via a POST request that uses tools/_rcmdstat.jsp to write to a specified filename.
|
CWE-20
Improper Input Validation
|
CVE-2019-19836
|
2024-11-21 13:35 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223260
|
7.2 |
HIGH
Network
|
ruckuswireless
|
unleashed zonedirector_1200_firmware
|
Directory Traversal in ruckus_cli2 in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote attacker to jailbreak the CLI via enable->debug->script->exec with ../../../bin/sh as the param…
|
CWE-22
Path Traversal
|
CVE-2019-19834
|
2024-11-21 13:35 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|