CVE-2020-8830

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
05/05/2020
Last modified:
21/07/2021

Description

CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field on the Wireless Admin screen.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:commscope:ruckus_zoneflex_r500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:commscope:ruckus_zoneflex_r500:-:*:*:*:*:*:*:*