Skip to content
Noroxi

commscope records

68 published records for vendor commscope.

All records

68 records
  • Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    ruckuswireless · ruckus wireless adminFeb 13, 2023

  • An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.

    CriticalCVSS 9.8Proof of conceptEPSS 56%

    commscope · ruckus iot controllerJul 7, 2021

  • Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py.

    CriticalCVSS 9.8Proof of conceptEPSS 45%

    commscope · ruckus vriotOct 26, 2020

  • Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.

    HighCVSS 8.8Proof of conceptEPSS 43%

    commscope · arris tg2482a firmwareFeb 17, 2023

  • An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.

    CriticalCVSS 9.8Proof of conceptEPSS 14%

    commscope · ruckus iot controllerJul 7, 2021

  • Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、d

    CriticalCVSS 9.8No exploitEPSS 5%

    commscope · arris tr3300 firmwareMar 15, 2022

  • Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin paramet

    CriticalCVSS 9.8No exploitEPSS 3%

    commscope · arris tr3300 firmwareMar 15, 2022

  • Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter.

    CriticalCVSS 9.8No exploitEPSS 3%

    commscope · arris tr3300 firmwareMar 15, 2022

  • Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wan

    CriticalCVSS 9.8No exploitEPSS 3%

    commscope · arris tr3300 firmwareMar 15, 2022

  • Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the upnp function via the upnp_ttl parameter.

    CriticalCVSS 9.8No exploitEPSS 3%

    commscope · arris tr3300 firmwareMar 15, 2022

  • Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_se

    CriticalCVSS 9.8No exploitEPSS 3%

    commscope · arris tr3300 firmwareMar 15, 2022

  • The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939

    CriticalCVSS 9.8No exploitEPSS 3%

    cisco · dpc3939 firmwareJul 30, 2017

  • Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoe_username, pppoe_passwd,

    CriticalCVSS 9.8No exploitEPSS 3%

    commscope · arris tr3300 firmwareMar 15, 2022

  • Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pptp (wan_pptp.html) function via the pptp_fix_ip, p

    CriticalCVSS 9.8No exploitEPSS 3%

    commscope · arris tr3300 firmwareMar 15, 2022

  • An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.

    CriticalCVSS 9.8No exploitEPSS 2%

    commscope · ruckus iot controllerJul 7, 2021

  • An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.

    CriticalCVSS 9.8No exploitEPSS 2%

    commscope · ruckus iot controllerJul 7, 2021

  • ARRIS SBG6580-2 D30GW-SEAEAGLE-1.5.2.5-GA-00-NOSH devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.

    CriticalCVSS 9.8No exploitEPSS 2%

    commscope · arris sbg6580-2 firmwareDec 23, 2018

  • ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0

    CriticalCVSS 9.8No exploitEPSS 2%

    arris · dg950s firmwareDec 23, 2018

  • An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addS

    CriticalCVSS 9.8No exploitEPSS 1%

    commscope · ruckus c110Jul 21, 2025

  • Arris SURFboard SBG6950AC2 Arbitrary Code Execution Vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    commscope · arris surfboard sbg6950ac2 firmwareJan 25, 2024

  • CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative inter

    CriticalCVSS 9.8No exploitEPSS 1%

    commscope · tr4400 firmwareAug 29, 2019

  • CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative inter

    CriticalCVSS 9.8No exploitEPSS 1%

    commscope · tr4400 firmwareAug 29, 2019

  • An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.

    CriticalCVSS 9.8No exploitEPSS 1%

    commscope · ruckus c110Jul 21, 2025

  • RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.

    CriticalCVSS 9.8No exploitEPSS 1%

    commscope · ruckus smartzone firmwareAug 4, 2025

  • In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user.

    CriticalCVSS 9.8No exploitEPSS 1%

    commscope · ruckus network directorFeb 19, 2026