commscope kayıtları
commscope üreticisine ait 68 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %1,5
- Silahlaştırılmış
- 2 · %2,9
- Pre-auth RCE
- 14
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- 88 gün
Tekrar eden sınıflar
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')11
- CWE-798 Use of Hard-coded Credentials7
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
68 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
98Hemen | CVE-2023-25717Silahlaştırılmış | Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLoginruckuswireless · ruckus wireless admin · CWE-94 | Kritik9,8 | KEV | %98,1 | 13 Şub 2023 |
56Planlayın | CVE-2021-33221Kavram kanıtı | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.commscope · ruckus iot controller · CWE-306 | Kritik9,8 | — | %56,1 | 7 Tem 2021 |
53Planlayın | CVE-2020-26879Kavram kanıtı | Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py.commscope · ruckus vriot · CWE-798 | Kritik9,8 | — | %45,1 | 26 Eki 2020 |
48Planlayın | CVE-2022-45701Kavram kanıtı | Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.commscope · arris tg2482a firmware · CWE-77 | Yüksek8,8 | — | %42,6 | 17 Şub 2023 |
43Planlayın | CVE-2021-33216Kavram kanıtı | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.commscope · ruckus iot controller | Kritik9,8 | — | %13,8 | 7 Tem 2021 |
41Planlayın | CVE-2022-27002İstismar yok | Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、dcommscope · arris tr3300 firmware · CWE-77 | Kritik9,8 | — | %5,1 | 15 Mar 2022 |
40Planlayın | CVE-2022-26998İstismar yok | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin parametcommscope · arris tr3300 firmware · CWE-77 | Kritik9,8 | — | %3,4 | 15 Mar 2022 |
40Planlayın | CVE-2022-27001İstismar yok | Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter.commscope · arris tr3300 firmware · CWE-77 | Kritik9,8 | — | %3,4 | 15 Mar 2022 |
40Planlayın | CVE-2022-26999İstismar yok | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wancommscope · arris tr3300 firmware · CWE-77 | Kritik9,8 | — | %3,4 | 15 Mar 2022 |
40Planlayın | CVE-2022-26997İstismar yok | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the upnp function via the upnp_ttl parameter.commscope · arris tr3300 firmware · CWE-77 | Kritik9,8 | — | %3,4 | 15 Mar 2022 |
40Planlayın | CVE-2022-27000İstismar yok | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_secommscope · arris tr3300 firmware · CWE-77 | Kritik9,8 | — | %3,4 | 15 Mar 2022 |
40Planlayın | CVE-2017-9521İstismar yok | The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939cisco · dpc3939 firmware | Kritik9,8 | — | %3,3 | 30 Tem 2017 |
40Planlayın | CVE-2022-26996İstismar yok | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoe_username, pppoe_passwd,commscope · arris tr3300 firmware · CWE-77 | Kritik9,8 | — | %2,9 | 15 Mar 2022 |
40Planlayın | CVE-2022-26995İstismar yok | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pptp (wan_pptp.html) function via the pptp_fix_ip, pcommscope · arris tr3300 firmware · CWE-77 | Kritik9,8 | — | %2,9 | 15 Mar 2022 |
40Planlayın | CVE-2021-33218İstismar yok | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.commscope · ruckus iot controller · CWE-798 | Kritik9,8 | — | %2,3 | 7 Tem 2021 |
40Planlayın | CVE-2021-33219İstismar yok | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.commscope · ruckus iot controller · CWE-798 | Kritik9,8 | — | %2,2 | 7 Tem 2021 |
40Planlayın | CVE-2018-20386İstismar yok | ARRIS SBG6580-2 D30GW-SEAEAGLE-1.5.2.5-GA-00-NOSH devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.commscope · arris sbg6580-2 firmware · CWE-522 | Kritik9,8 | — | %1,8 | 23 Ara 2018 |
40Planlayın | CVE-2018-20383İstismar yok | ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0arris · dg950s firmware · CWE-522 | Kritik9,8 | — | %1,8 | 23 Ara 2018 |
39İzleyin | CVE-2025-46121İstismar yok | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addScommscope · ruckus c110 · CWE-134 | Kritik9,8 | — | %1,3 | 21 Tem 2025 |
39İzleyin | CVE-2024-23618İstismar yok | Arris SURFboard SBG6950AC2 Arbitrary Code Execution Vulnerabilitycommscope · arris surfboard sbg6950ac2 firmware · CWE-306 | Kritik9,8 | — | %1,2 | 25 Oca 2024 |
39İzleyin | CVE-2019-15806İstismar yok | CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative intercommscope · tr4400 firmware · CWE-326 | Kritik9,8 | — | %1,2 | 29 Ağu 2019 |
39İzleyin | CVE-2019-15805İstismar yok | CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative intercommscope · tr4400 firmware · CWE-326 | Kritik9,8 | — | %1,2 | 29 Ağu 2019 |
39İzleyin | CVE-2025-46120İstismar yok | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.commscope · ruckus c110 · CWE-22 | Kritik9,8 | — | %1,0 | 21 Tem 2025 |
39İzleyin | CVE-2025-44954İstismar yok | RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.commscope · ruckus smartzone firmware · CWE-1394 | Kritik9,8 | — | %0,7 | 4 Ağu 2025 |
39İzleyin | CVE-2025-67305İstismar yok | In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user.commscope · ruckus network director · CWE-321 | Kritik9,8 | — | %0,5 | 19 Şub 2026 |
- CVE-2023-2571798Hemen
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98ruckuswireless · ruckus wireless admin13 Şub 2023
- CVE-2021-3322156Planlayın
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.
KritikCVSS 9,8Kavram kanıtıEPSS %56commscope · ruckus iot controller7 Tem 2021
- CVE-2020-2687953Planlayın
Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py.
KritikCVSS 9,8Kavram kanıtıEPSS %45commscope · ruckus vriot26 Eki 2020
- CVE-2022-4570148Planlayın
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
YüksekCVSS 8,8Kavram kanıtıEPSS %43commscope · arris tg2482a firmware17 Şub 2023
- CVE-2021-3321643Planlayın
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.
KritikCVSS 9,8Kavram kanıtıEPSS %14commscope · ruckus iot controller7 Tem 2021
- CVE-2022-2700241Planlayın
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、d
KritikCVSS 9,8İstismar yokEPSS %5commscope · arris tr3300 firmware15 Mar 2022
- CVE-2022-2699840Planlayın
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin paramet
KritikCVSS 9,8İstismar yokEPSS %3commscope · arris tr3300 firmware15 Mar 2022
- CVE-2022-2700140Planlayın
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter.
KritikCVSS 9,8İstismar yokEPSS %3commscope · arris tr3300 firmware15 Mar 2022
- CVE-2022-2699940Planlayın
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wan
KritikCVSS 9,8İstismar yokEPSS %3commscope · arris tr3300 firmware15 Mar 2022
- CVE-2022-2699740Planlayın
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the upnp function via the upnp_ttl parameter.
KritikCVSS 9,8İstismar yokEPSS %3commscope · arris tr3300 firmware15 Mar 2022
- CVE-2022-2700040Planlayın
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_se
KritikCVSS 9,8İstismar yokEPSS %3commscope · arris tr3300 firmware15 Mar 2022
- CVE-2017-952140Planlayın
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939
KritikCVSS 9,8İstismar yokEPSS %3cisco · dpc3939 firmware30 Tem 2017
- CVE-2022-2699640Planlayın
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoe_username, pppoe_passwd,
KritikCVSS 9,8İstismar yokEPSS %3commscope · arris tr3300 firmware15 Mar 2022
- CVE-2022-2699540Planlayın
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pptp (wan_pptp.html) function via the pptp_fix_ip, p
KritikCVSS 9,8İstismar yokEPSS %3commscope · arris tr3300 firmware15 Mar 2022
- CVE-2021-3321840Planlayın
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.
KritikCVSS 9,8İstismar yokEPSS %2commscope · ruckus iot controller7 Tem 2021
- CVE-2021-3321940Planlayın
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.
KritikCVSS 9,8İstismar yokEPSS %2commscope · ruckus iot controller7 Tem 2021
- CVE-2018-2038640Planlayın
ARRIS SBG6580-2 D30GW-SEAEAGLE-1.5.2.5-GA-00-NOSH devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.
KritikCVSS 9,8İstismar yokEPSS %2commscope · arris sbg6580-2 firmware23 Ara 2018
- CVE-2018-2038340Planlayın
ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0
KritikCVSS 9,8İstismar yokEPSS %2arris · dg950s firmware23 Ara 2018
- CVE-2025-4612139İzleyin
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addS
KritikCVSS 9,8İstismar yokEPSS %1commscope · ruckus c11021 Tem 2025
- CVE-2024-2361839İzleyin
Arris SURFboard SBG6950AC2 Arbitrary Code Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1commscope · arris surfboard sbg6950ac2 firmware25 Oca 2024
- CVE-2019-1580639İzleyin
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative inter
KritikCVSS 9,8İstismar yokEPSS %1commscope · tr4400 firmware29 Ağu 2019
- CVE-2019-1580539İzleyin
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative inter
KritikCVSS 9,8İstismar yokEPSS %1commscope · tr4400 firmware29 Ağu 2019
- CVE-2025-4612039İzleyin
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.
KritikCVSS 9,8İstismar yokEPSS %1commscope · ruckus c11021 Tem 2025
- CVE-2025-4495439İzleyin
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.
KritikCVSS 9,8İstismar yokEPSS %1commscope · ruckus smartzone firmware4 Ağu 2025
- CVE-2025-6730539İzleyin
In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user.
KritikCVSS 9,8İstismar yokEPSS %1commscope · ruckus network director19 Şub 2026