CVE-2021-33217

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
07/07/2021
Last modified:
09/07/2021

Description

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The Web Application allows Arbitrary Read/Write actions by authenticated users. The API allows an HTTP POST of arbitrary content into any file on the filesystem as root.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:commscope:ruckus_iot_controller:*:*:*:*:*:*:*:* 1.7.1.0 (including)