• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-19841
Ruckuswireless, Zonedirector 1200 Firmware
Unleashed, C110, E510, H320, H510, M510, R310, R320, R510, R610
2020-01-28
N/A
9.8 CRITICAL
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=packet-capture to admin/_cmdstat.jsp via the mac attribute.
CVE-2019-19840
Ruckuswireless, Zonedirector 1200 Firmware
Unleashed, C110, E510, H320, H510, M510, R310, R320, R510, R610
2020-01-27
N/A
9.8 CRITICAL
A stack-based buffer overflow in zap_parse_args in zap.c in zap in Ruckus Unleashed through 200.7.10.102.64 allows remote code execution via an unauthenticated HTTP request.
CVE-2019-1984
2019-10-09
N/A
6.5 MEDIUM
A vulnerability in Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker with administrator privileges to overwrite files on the underlying operating system (OS) of an affected device. The vulnerability is due to improper input validation in an NFVIS file-system command. An attacker could exploit this vulnerability by using crafted variables during the execution of an affected command. A successful exploit could allow the attacker to overwrite arbitrary files on the underlying OS.
CVE-2019-19839
Ruckuswireless, Zonedirector 1200 Firmware
Unleashed, C110, E510, H320, H510, M510, R310, R320, R510, R610
2020-01-23
N/A
9.8 CRITICAL
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=import-category to admin/_cmdstat.jsp via the uploadFile attribute.
CVE-2019-19838
Ruckuswireless, Zonedirector 1200 Firmware
Unleashed, C110, E510, H320, H510, M510, R310, R320, R510, R610
2020-01-23
N/A
9.8 CRITICAL
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=get-platform-depends to admin/_cmdstat.jsp via the uploadFile attribute.
CVE-2019-19837
Ruckuswireless, Zonedirector 1200 Firmware
Unleashed, C110, E510, H320, H510, M510, R310, R320, R510, R610
2021-07-21
N/A
5.3 MEDIUM
Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote information disclosure of bin/web.conf via HTTP requests.
CVE-2019-19836
Ruckuswireless, Zonedirector 1200 Firmware
Unleashed, C110, E510, H320, H510, M510, R310, R320, R510, R610
2020-01-23
N/A
9.8 CRITICAL
AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote code execution via a POST request that uses tools/_rcmdstat.jsp to write to a specified filename.
CVE-2019-19835
Ruckuswireless, Zonedirector 1200 Firmware
Unleashed, C110, E510, H320, H510, M510, R310, R320, R510, R610
2020-01-27
N/A
7.5 HIGH
SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of service via the server attribute to the tools/_rcmdstat.jsp URI.
CVE-2019-19834
Ruckuswireless, Zonedirector 1200 Firmware
Unleashed, C110, E510, H320, H510, M510, R310, R320, R510, R610
2020-01-23
N/A
7.2 HIGH
Directory Traversal in ruckus_cli2 in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote attacker to jailbreak the CLI via enable->debug->script->exec with ../../../bin/sh as the parameter.
CVE-2019-19833
2023-02-01
N/A
6.5 MEDIUM
In Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media server. (Also, anonymous access can be achieved in applications that do not have a user login area).
« Previous 1 … 5,763 5,764 5,765 5,766 5,767 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE