commscope records
68 published records for vendor commscope.
Researcher profile
- Entered KEV
- 1 · 1.5%
- Weaponized
- 2 · 2.9%
- Pre-auth RCE
- 14
- With a fix record
- 0%
- Median publish → KEV
- 88 days
Recurring classes
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')11
- CWE-798 Use of Hard-coded Credentials7
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
The weakness classes this vendor ships most often: where to look.
CWEAll records
68 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
98Now | CVE-2023-25717Weaponized | Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLoginruckuswireless · ruckus wireless admin · CWE-94 | Critical9.8 | KEV | 98.1% | Feb 13, 2023 |
56Plan | CVE-2021-33221Proof of concept | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.commscope · ruckus iot controller · CWE-306 | Critical9.8 | — | 56.1% | Jul 7, 2021 |
53Plan | CVE-2020-26879Proof of concept | Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py.commscope · ruckus vriot · CWE-798 | Critical9.8 | — | 45.1% | Oct 26, 2020 |
48Plan | CVE-2022-45701Proof of concept | Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.commscope · arris tg2482a firmware · CWE-77 | High8.8 | — | 42.6% | Feb 17, 2023 |
43Plan | CVE-2021-33216Proof of concept | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.commscope · ruckus iot controller | Critical9.8 | — | 13.8% | Jul 7, 2021 |
41Plan | CVE-2022-27002No exploit | Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、dcommscope · arris tr3300 firmware · CWE-77 | Critical9.8 | — | 5.1% | Mar 15, 2022 |
40Plan | CVE-2022-26998No exploit | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin parametcommscope · arris tr3300 firmware · CWE-77 | Critical9.8 | — | 3.4% | Mar 15, 2022 |
40Plan | CVE-2022-27001No exploit | Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter.commscope · arris tr3300 firmware · CWE-77 | Critical9.8 | — | 3.4% | Mar 15, 2022 |
40Plan | CVE-2022-26999No exploit | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wancommscope · arris tr3300 firmware · CWE-77 | Critical9.8 | — | 3.4% | Mar 15, 2022 |
40Plan | CVE-2022-26997No exploit | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the upnp function via the upnp_ttl parameter.commscope · arris tr3300 firmware · CWE-77 | Critical9.8 | — | 3.4% | Mar 15, 2022 |
40Plan | CVE-2022-27000No exploit | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_secommscope · arris tr3300 firmware · CWE-77 | Critical9.8 | — | 3.4% | Mar 15, 2022 |
40Plan | CVE-2017-9521No exploit | The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939cisco · dpc3939 firmware | Critical9.8 | — | 3.3% | Jul 30, 2017 |
40Plan | CVE-2022-26996No exploit | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoe_username, pppoe_passwd,commscope · arris tr3300 firmware · CWE-77 | Critical9.8 | — | 2.9% | Mar 15, 2022 |
40Plan | CVE-2022-26995No exploit | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pptp (wan_pptp.html) function via the pptp_fix_ip, pcommscope · arris tr3300 firmware · CWE-77 | Critical9.8 | — | 2.9% | Mar 15, 2022 |
40Plan | CVE-2021-33218No exploit | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.commscope · ruckus iot controller · CWE-798 | Critical9.8 | — | 2.3% | Jul 7, 2021 |
40Plan | CVE-2021-33219No exploit | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.commscope · ruckus iot controller · CWE-798 | Critical9.8 | — | 2.2% | Jul 7, 2021 |
40Plan | CVE-2018-20386No exploit | ARRIS SBG6580-2 D30GW-SEAEAGLE-1.5.2.5-GA-00-NOSH devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.commscope · arris sbg6580-2 firmware · CWE-522 | Critical9.8 | — | 1.8% | Dec 23, 2018 |
40Plan | CVE-2018-20383No exploit | ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0arris · dg950s firmware · CWE-522 | Critical9.8 | — | 1.8% | Dec 23, 2018 |
39Monitor | CVE-2025-46121No exploit | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addScommscope · ruckus c110 · CWE-134 | Critical9.8 | — | 1.3% | Jul 21, 2025 |
39Monitor | CVE-2024-23618No exploit | Arris SURFboard SBG6950AC2 Arbitrary Code Execution Vulnerabilitycommscope · arris surfboard sbg6950ac2 firmware · CWE-306 | Critical9.8 | — | 1.2% | Jan 25, 2024 |
39Monitor | CVE-2019-15806No exploit | CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative intercommscope · tr4400 firmware · CWE-326 | Critical9.8 | — | 1.2% | Aug 29, 2019 |
39Monitor | CVE-2019-15805No exploit | CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative intercommscope · tr4400 firmware · CWE-326 | Critical9.8 | — | 1.2% | Aug 29, 2019 |
39Monitor | CVE-2025-46120No exploit | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.commscope · ruckus c110 · CWE-22 | Critical9.8 | — | 1.0% | Jul 21, 2025 |
39Monitor | CVE-2025-44954No exploit | RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.commscope · ruckus smartzone firmware · CWE-1394 | Critical9.8 | — | 0.7% | Aug 4, 2025 |
39Monitor | CVE-2025-67305No exploit | In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user.commscope · ruckus network director · CWE-321 | Critical9.8 | — | 0.5% | Feb 19, 2026 |
- CVE-2023-2571798Now
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin
CriticalCVSS 9.8KEVWeaponizedEPSS 98%ruckuswireless · ruckus wireless adminFeb 13, 2023
- CVE-2021-3322156Plan
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.
CriticalCVSS 9.8Proof of conceptEPSS 56%commscope · ruckus iot controllerJul 7, 2021
- CVE-2020-2687953Plan
Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py.
CriticalCVSS 9.8Proof of conceptEPSS 45%commscope · ruckus vriotOct 26, 2020
- CVE-2022-4570148Plan
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
HighCVSS 8.8Proof of conceptEPSS 43%commscope · arris tg2482a firmwareFeb 17, 2023
- CVE-2021-3321643Plan
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.
CriticalCVSS 9.8Proof of conceptEPSS 14%commscope · ruckus iot controllerJul 7, 2021
- CVE-2022-2700241Plan
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、d
CriticalCVSS 9.8No exploitEPSS 5%commscope · arris tr3300 firmwareMar 15, 2022
- CVE-2022-2699840Plan
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin paramet
CriticalCVSS 9.8No exploitEPSS 3%commscope · arris tr3300 firmwareMar 15, 2022
- CVE-2022-2700140Plan
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter.
CriticalCVSS 9.8No exploitEPSS 3%commscope · arris tr3300 firmwareMar 15, 2022
- CVE-2022-2699940Plan
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wan
CriticalCVSS 9.8No exploitEPSS 3%commscope · arris tr3300 firmwareMar 15, 2022
- CVE-2022-2699740Plan
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the upnp function via the upnp_ttl parameter.
CriticalCVSS 9.8No exploitEPSS 3%commscope · arris tr3300 firmwareMar 15, 2022
- CVE-2022-2700040Plan
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_se
CriticalCVSS 9.8No exploitEPSS 3%commscope · arris tr3300 firmwareMar 15, 2022
- CVE-2017-952140Plan
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939
CriticalCVSS 9.8No exploitEPSS 3%cisco · dpc3939 firmwareJul 30, 2017
- CVE-2022-2699640Plan
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoe_username, pppoe_passwd,
CriticalCVSS 9.8No exploitEPSS 3%commscope · arris tr3300 firmwareMar 15, 2022
- CVE-2022-2699540Plan
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pptp (wan_pptp.html) function via the pptp_fix_ip, p
CriticalCVSS 9.8No exploitEPSS 3%commscope · arris tr3300 firmwareMar 15, 2022
- CVE-2021-3321840Plan
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.
CriticalCVSS 9.8No exploitEPSS 2%commscope · ruckus iot controllerJul 7, 2021
- CVE-2021-3321940Plan
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.
CriticalCVSS 9.8No exploitEPSS 2%commscope · ruckus iot controllerJul 7, 2021
- CVE-2018-2038640Plan
ARRIS SBG6580-2 D30GW-SEAEAGLE-1.5.2.5-GA-00-NOSH devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.
CriticalCVSS 9.8No exploitEPSS 2%commscope · arris sbg6580-2 firmwareDec 23, 2018
- CVE-2018-2038340Plan
ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0
CriticalCVSS 9.8No exploitEPSS 2%arris · dg950s firmwareDec 23, 2018
- CVE-2025-4612139Monitor
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addS
CriticalCVSS 9.8No exploitEPSS 1%commscope · ruckus c110Jul 21, 2025
- CVE-2024-2361839Monitor
Arris SURFboard SBG6950AC2 Arbitrary Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%commscope · arris surfboard sbg6950ac2 firmwareJan 25, 2024
- CVE-2019-1580639Monitor
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative inter
CriticalCVSS 9.8No exploitEPSS 1%commscope · tr4400 firmwareAug 29, 2019
- CVE-2019-1580539Monitor
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative inter
CriticalCVSS 9.8No exploitEPSS 1%commscope · tr4400 firmwareAug 29, 2019
- CVE-2025-4612039Monitor
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.
CriticalCVSS 9.8No exploitEPSS 1%commscope · ruckus c110Jul 21, 2025
- CVE-2025-4495439Monitor
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.
CriticalCVSS 9.8No exploitEPSS 1%commscope · ruckus smartzone firmwareAug 4, 2025
- CVE-2025-6730539Monitor
In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user.
CriticalCVSS 9.8No exploitEPSS 1%commscope · ruckus network directorFeb 19, 2026