Записи commscope
68 опубликованных записей вендора commscope.
Профиль для исследователя
- Попали в KEV
- 1 · 1,5 %
- С эксплойтом
- 2 · 2,9 %
- Pre-auth RCE
- 14
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- 88 дн.
Повторяющиеся классы
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')11
- CWE-798 Use of Hard-coded Credentials7
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
68 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
98Срочно | CVE-2023-25717Готовый эксплойт | Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLoginruckuswireless · ruckus wireless admin · CWE-94 | Критическая9,8 | KEV | 98,1 % | 13 февр. 2023 г. |
56В плане | CVE-2021-33221Proof of concept | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.commscope · ruckus iot controller · CWE-306 | Критическая9,8 | — | 56,1 % | 7 июл. 2021 г. |
53В плане | CVE-2020-26879Proof of concept | Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py.commscope · ruckus vriot · CWE-798 | Критическая9,8 | — | 45,1 % | 26 окт. 2020 г. |
48В плане | CVE-2022-45701Proof of concept | Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.commscope · arris tg2482a firmware · CWE-77 | Высокая8,8 | — | 42,6 % | 17 февр. 2023 г. |
43В плане | CVE-2021-33216Proof of concept | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.commscope · ruckus iot controller | Критическая9,8 | — | 13,8 % | 7 июл. 2021 г. |
41В плане | CVE-2022-27002Эксплойта нет | Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、dcommscope · arris tr3300 firmware · CWE-77 | Критическая9,8 | — | 5,1 % | 15 мар. 2022 г. |
40В плане | CVE-2022-26998Эксплойта нет | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin parametcommscope · arris tr3300 firmware · CWE-77 | Критическая9,8 | — | 3,4 % | 15 мар. 2022 г. |
40В плане | CVE-2022-27001Эксплойта нет | Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter.commscope · arris tr3300 firmware · CWE-77 | Критическая9,8 | — | 3,4 % | 15 мар. 2022 г. |
40В плане | CVE-2022-26999Эксплойта нет | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wancommscope · arris tr3300 firmware · CWE-77 | Критическая9,8 | — | 3,4 % | 15 мар. 2022 г. |
40В плане | CVE-2022-26997Эксплойта нет | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the upnp function via the upnp_ttl parameter.commscope · arris tr3300 firmware · CWE-77 | Критическая9,8 | — | 3,4 % | 15 мар. 2022 г. |
40В плане | CVE-2022-27000Эксплойта нет | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_secommscope · arris tr3300 firmware · CWE-77 | Критическая9,8 | — | 3,4 % | 15 мар. 2022 г. |
40В плане | CVE-2017-9521Эксплойта нет | The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939cisco · dpc3939 firmware | Критическая9,8 | — | 3,3 % | 30 июл. 2017 г. |
40В плане | CVE-2022-26996Эксплойта нет | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoe_username, pppoe_passwd,commscope · arris tr3300 firmware · CWE-77 | Критическая9,8 | — | 2,9 % | 15 мар. 2022 г. |
40В плане | CVE-2022-26995Эксплойта нет | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pptp (wan_pptp.html) function via the pptp_fix_ip, pcommscope · arris tr3300 firmware · CWE-77 | Критическая9,8 | — | 2,9 % | 15 мар. 2022 г. |
40В плане | CVE-2021-33218Эксплойта нет | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.commscope · ruckus iot controller · CWE-798 | Критическая9,8 | — | 2,3 % | 7 июл. 2021 г. |
40В плане | CVE-2021-33219Эксплойта нет | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.commscope · ruckus iot controller · CWE-798 | Критическая9,8 | — | 2,2 % | 7 июл. 2021 г. |
40В плане | CVE-2018-20386Эксплойта нет | ARRIS SBG6580-2 D30GW-SEAEAGLE-1.5.2.5-GA-00-NOSH devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.commscope · arris sbg6580-2 firmware · CWE-522 | Критическая9,8 | — | 1,8 % | 23 дек. 2018 г. |
40В плане | CVE-2018-20383Эксплойта нет | ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0arris · dg950s firmware · CWE-522 | Критическая9,8 | — | 1,8 % | 23 дек. 2018 г. |
39Наблюдать | CVE-2025-46121Эксплойта нет | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addScommscope · ruckus c110 · CWE-134 | Критическая9,8 | — | 1,3 % | 21 июл. 2025 г. |
39Наблюдать | CVE-2024-23618Эксплойта нет | Arris SURFboard SBG6950AC2 Arbitrary Code Execution Vulnerabilitycommscope · arris surfboard sbg6950ac2 firmware · CWE-306 | Критическая9,8 | — | 1,2 % | 25 янв. 2024 г. |
39Наблюдать | CVE-2019-15806Эксплойта нет | CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative intercommscope · tr4400 firmware · CWE-326 | Критическая9,8 | — | 1,2 % | 29 авг. 2019 г. |
39Наблюдать | CVE-2019-15805Эксплойта нет | CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative intercommscope · tr4400 firmware · CWE-326 | Критическая9,8 | — | 1,2 % | 29 авг. 2019 г. |
39Наблюдать | CVE-2025-46120Эксплойта нет | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.commscope · ruckus c110 · CWE-22 | Критическая9,8 | — | 1,0 % | 21 июл. 2025 г. |
39Наблюдать | CVE-2025-44954Эксплойта нет | RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.commscope · ruckus smartzone firmware · CWE-1394 | Критическая9,8 | — | 0,7 % | 4 авг. 2025 г. |
39Наблюдать | CVE-2025-67305Эксплойта нет | In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user.commscope · ruckus network director · CWE-321 | Критическая9,8 | — | 0,5 % | 19 февр. 2026 г. |
- CVE-2023-2571798Срочно
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %ruckuswireless · ruckus wireless admin13 февр. 2023 г.
- CVE-2021-3322156В плане
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.
КритическаяCVSS 9,8Proof of conceptEPSS 56 %commscope · ruckus iot controller7 июл. 2021 г.
- CVE-2020-2687953В плане
Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py.
КритическаяCVSS 9,8Proof of conceptEPSS 45 %commscope · ruckus vriot26 окт. 2020 г.
- CVE-2022-4570148В плане
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
ВысокаяCVSS 8,8Proof of conceptEPSS 43 %commscope · arris tg2482a firmware17 февр. 2023 г.
- CVE-2021-3321643В плане
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.
КритическаяCVSS 9,8Proof of conceptEPSS 14 %commscope · ruckus iot controller7 июл. 2021 г.
- CVE-2022-2700241В плане
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、d
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %commscope · arris tr3300 firmware15 мар. 2022 г.
- CVE-2022-2699840В плане
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin paramet
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %commscope · arris tr3300 firmware15 мар. 2022 г.
- CVE-2022-2700140В плане
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %commscope · arris tr3300 firmware15 мар. 2022 г.
- CVE-2022-2699940В плане
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wan
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %commscope · arris tr3300 firmware15 мар. 2022 г.
- CVE-2022-2699740В плане
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the upnp function via the upnp_ttl parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %commscope · arris tr3300 firmware15 мар. 2022 г.
- CVE-2022-2700040В плане
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_se
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %commscope · arris tr3300 firmware15 мар. 2022 г.
- CVE-2017-952140В плане
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %cisco · dpc3939 firmware30 июл. 2017 г.
- CVE-2022-2699640В плане
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoe_username, pppoe_passwd,
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %commscope · arris tr3300 firmware15 мар. 2022 г.
- CVE-2022-2699540В плане
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pptp (wan_pptp.html) function via the pptp_fix_ip, p
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %commscope · arris tr3300 firmware15 мар. 2022 г.
- CVE-2021-3321840В плане
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %commscope · ruckus iot controller7 июл. 2021 г.
- CVE-2021-3321940В плане
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %commscope · ruckus iot controller7 июл. 2021 г.
- CVE-2018-2038640В плане
ARRIS SBG6580-2 D30GW-SEAEAGLE-1.5.2.5-GA-00-NOSH devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %commscope · arris sbg6580-2 firmware23 дек. 2018 г.
- CVE-2018-2038340В плане
ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %arris · dg950s firmware23 дек. 2018 г.
- CVE-2025-4612139Наблюдать
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addS
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %commscope · ruckus c11021 июл. 2025 г.
- CVE-2024-2361839Наблюдать
Arris SURFboard SBG6950AC2 Arbitrary Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %commscope · arris surfboard sbg6950ac2 firmware25 янв. 2024 г.
- CVE-2019-1580639Наблюдать
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative inter
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %commscope · tr4400 firmware29 авг. 2019 г.
- CVE-2019-1580539Наблюдать
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative inter
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %commscope · tr4400 firmware29 авг. 2019 г.
- CVE-2025-4612039Наблюдать
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %commscope · ruckus c11021 июл. 2025 г.
- CVE-2025-4495439Наблюдать
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %commscope · ruckus smartzone firmware4 авг. 2025 г.
- CVE-2025-6730539Наблюдать
In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %commscope · ruckus network director19 февр. 2026 г.