Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-20349 · Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability · Added 2026-08-11 · Due 2026-08-14CISA KEV · CVE-2026-68820 · Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability · Added 2026-08-11 · Due 2026-08-25NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-20349 · Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability · Added 2026-08-11 · Due 2026-08-14CISA KEV · CVE-2026-68820 · Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability · Added 2026-08-11 · Due 2026-08-25

Vendors · commscope

commscope

· 28 Critical

Total CVEs

68

Critical

28

Products

96

Search All CVEs →

68

Products (96)

ruckus c11013 CVEsruckus t750se13 CVEsruckus t75013 CVEsruckus t350se13 CVEsruckus t310s13 CVEsruckus t310n13 CVEsruckus t310c13 CVEsruckus r75013 CVEsruckus r73013 CVEsruckus r72013 CVEsruckus r71013 CVEsruckus r61013 CVEsruckus r56013 CVEsruckus r51013 CVEsruckus r32013 CVEsruckus h32013 CVEsruckus e51013 CVEsruckus m51013 CVEsruckus h51013 CVEsruckus h35013 CVEsruckus network director9 CVEsarris tg1682g9 CVEszonedirector 12008 CVEsarris tg1682g firmware8 CVEsarris tr33008 CVEsarris tr3300 firmware8 CVEsruckus h5508 CVEsruckus m510-jp8 CVEsruckus r3108 CVEsruckus r3508 CVEsruckus r350e8 CVEsruckus r5508 CVEsruckus r6508 CVEsruckus r6708 CVEsruckus r7608 CVEsruckus r7708 CVEsruckus r8508 CVEsruckus t350c8 CVEsruckus t350d8 CVEsruckus t6108 CVEsruckus t6708 CVEsruckus t7108 CVEsruckus t710s8 CVEsruckus t811-cm8 CVEsruckus t811-cm \(non-sfp\)8 CVEsruckus iot controller7 CVEsruckus smartzone firmware6 CVEsruckus t310d5 CVEsruckus virtual smartzone5 CVEsruckus smartzone 3005 CVEsruckus smartzone 144-federal5 CVEsruckus smartzone 1445 CVEsruckus smartzone 100-d5 CVEsruckus smartzone 1005 CVEsruckus smartzone 300-federal5 CVEsruckus virtual smartzone-federal5 CVEsarris nvg5994 CVEsruckus zoneflex r500 firmware3 CVEsarris nvg5893 CVEsruckus zoneflex r5003 CVEsdg3450 firmware2 CVEsarris surfboard sbg6950ac2 firmware2 CVEsdg34502 CVEstr4400 firmware2 CVEsruckus vriot2 CVEsarris surfboard sbg6950ac22 CVEsarris surfboard sb82002 CVEstr44002 CVEsarris surfboard sb8200 firmware2 CVEsruckus iot module2 CVEsarris surfboard sbg7400ac2 firmware1 CVEsarris surfboard sbg7600ac21 CVEsarris surfboard sbg10 firmware1 CVEsarris surfboard sbg101 CVEsarris dg950s1 CVEsarris sbg9011 CVEsarris sbg6580-2 firmware1 CVEsarris sbg6580-21 CVEsarris dg950a firmware1 CVEsarris dg950a1 CVEsruckus smartzone1 CVEsarris sbg10 firmware1 CVEsarris tg1692a1 CVEsarris tg1692a firmware1 CVEsarris tg2482a1 CVEsarris tg2482a firmware1 CVEsarris tg24921 CVEsarris tg2492 firmware1 CVEsarris tg2492lg-na1 CVEsarris tg2492lg-na firmware1 CVEsarris sbg101 CVEsarris surfboard sbg7600ac2 firmware1 CVEsruckus cloudpath enrollment system1 CVEsarris surfboard sbg7400ac21 CVEsarris surfboard sbg7580ac firmware1 CVEsarris surfboard sbg7580ac1 CVEs

Recent Vulnerabilities

View all 68
CVE-2025-67305CRITICAL 9.8

In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These keys are identical across all deployments, allowing an attacker with network access to authenticate via SSH without a password. Once authenticated, the attacker can access the PostgreSQL database with superuser privileges, create administrative users for the web interface, and potentially escalate privileges further.

CVE-2025-67304CRITICAL 9.8

In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default configuration, the PostgreSQL service is accessible over the network on TCP port 5432. An attacker can use the hardcoded credentials to authenticate remotely, gaining superuser access to the database. This allows creation of administrative users for the web interface, extraction of password hashes, and execution of arbitrary OS commands.

CVE-2025-44963CRITICAL 9.0

RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.

CVE-2025-44962MEDIUM 5.0

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files.

CVE-2025-44961CRITICAL 9.9

In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.

CVE-2025-44960HIGH 8.5

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.

CVE-2025-44958MEDIUM 5.3

RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format.

CVE-2025-44957HIGH 8.5

Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers.

CVE-2025-44954CRITICAL 9.0

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.

CVE-2025-44955HIGH 8.8

RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password.

CVE-2025-46123HIGH 7.2

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where the authenticated configuration endpoint `/admin/_conf.jsp` writes the Wi-Fi guest password to memory with snprintf using the attacker-supplied value as the format string; a crafted password therefore triggers uncontrolled format-string processing and enables remote code execution on the controller.

CVE-2025-46122CRITICAL 9.1

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled input to the shell without adequate validation, enabling a remote attacker to specify a target by MAC address and execute arbitrary commands as root.

CVE-2025-46121CRITICAL 9.8

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to snprintf as the format string. A remote attacker can exploit this flaw either by sending a crafted request to the authenticated endpoint `/admin/_conf.jsp`, or without authentication and without direct network access to the controller by spoofing the MAC address of a favourite station and embedding malicious format specifiers in the DHCP hostname field, resulting in unauthenticated format-string processing and arbitrary code execution on the controller.

CVE-2025-46120CRITICAL 9.8

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates outside permitted directories, allowing a remote unauthenticated attacker who can upload a template (e.g., via FTP) to escalate privileges and run arbitrary template code on the controller.

CVE-2025-46119MEDIUM 6.3

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where an authenticated request to the management endpoint `/admin/_cmdstat.jsp` discloses the administrator password in a trivially reversible obfuscated form. The same obfuscation method persists in configuration prior to 200.18.7.1.302, allowing anyone who obtains the system configuration to recover the plaintext credentials.

CVE-2025-46118MEDIUM 5.3

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remote attacker to upload or retrieve arbitrary files from writable firmware directories and thereby expose sensitive information or compromise the controller.

CVE-2025-46117CRITICAL 9.1

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where a hidden debug script `.ap_debug.sh` invoked from the restricted CLI does not properly sanitize its input, allowing an authenticated attacker to execute arbitrary commands as root on the controller or specified target.

CVE-2025-46116HIGH 8.8

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the passphrase requirement for a hidden CLI command `!v54!` via a management API call and then invoke it to escape the restricted shell and obtain a root shell on the controller.

CVE-2024-23618CRITICAL 9.6

An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can exploit this vulnerability to achieve code execution as root.

CVE-2023-49225MEDIUM 6.1

A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector, SmartZone, and AP Solo). If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in the product. As for the affected products/models/versions, see the information provided by the vendor listed under [References] section or the list under [Product Status] section.

CVE-2023-45992CRITICAL 9.6

A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user of the admin management interface. A successful attack, combined with a certain admin activity, could allow the attacker to gain full admin privileges on the exploited system.

CVE-2023-27572MEDIUM 6.1

An issue was discovered in CommScope Arris DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. A reflected XSS vulnerability was discovered in the https_redirect.php web page via the page parameter.

CVE-2023-27571MEDIUM 5.3

An issue was discovered in DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. The troubleshooting_logs_download.php log file download functionality does not check the session cookie. Thus, an attacker can download all log files.

CVE-2022-45701HIGH 8.8

Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.

CVE-2023-25717CRITICAL 9.8KEV

Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring.