CVE-2020-7983

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
05/05/2020
Last modified:
07/05/2020

Description

A CSRF issue in login.asp on Ruckus R500 3.4.2.0.384 devices allows remote attackers to access the panel or conduct SSRF attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:commscope:ruckus_zoneflex_r500_firmware:3.4.2.0.384:*:*:*:*:*:*:*
cpe:2.3:h:commscope:ruckus_zoneflex_r500:-:*:*:*:*:*:*:*