SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of service via the server attribute to the tools/_rcmdstat.jsp URI.
References
Link | Resource |
---|---|
https://alephsecurity.com/2020/01/14/ruckus-wireless | Exploit Technical Description Third Party Advisory |
https://www.ruckuswireless.com/security/299/view/txt | Vendor Advisory |
https://fahrplan.events.ccc.de/congress/2019/Fahrplan/events/10816.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Information
Published : 2020-01-23 05:15
Updated : 2020-01-27 05:00
NVD link : CVE-2019-19835
Mitre link : CVE-2019-19835
JSON object : View
CWE
CWE-918
Server-Side Request Forgery (SSRF)
Products Affected
ruckuswireless
- h510
- r510
- zonedirector_1200_firmware
- t310
- h320
- r320
- r610
- r710
- r720
- c110
- e510
- t610
- zonedirector_1200
- unleashed
- t710
- r310
- m510