CVE-2020-8438

Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hidden /forms/nslookupHandler form, as demonstrated by the nslookuptarget=|cat${IFS} substring.
References
Configurations

Configuration 1


Information

Published : 2020-01-29 11:15

Updated : 2020-01-31 08:32


NVD link : CVE-2020-8438

Mitre link : CVE-2020-8438

Products Affected
No products.
CWE