Commscope CommScope Ruckus IoT Controller是美国康普(Commscope)公司的一款物联网控制器。与SmartZone控制器集成的虚拟控制器,可为非Wi-Fi设备执行连接,设备和安全管理功能。 CommScope Ruckus IoT Controller 1.7.1.0 版本及之前版本中存在访问控制错误漏洞,该漏洞源于系统中有三个 API 端点无需身份验证即可访问,其中两个端点会导致信息泄漏和计算/存储资源的消耗,不需要身份验证的第三个 API 端点允许物联网控制
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CommScope Ruckus IoT Controller is susceptible to information disclosure vulnerabilities because a 'service details' API endpoint discloses system and configuration information to an attacker without requiring authentication. This information includes DNS and NTP servers that the devices use for time and host resolution. It also includes the internal hostname and IoT Controller version. A fully configured device in production may leak other, more sensitive information (API keys and tokens). | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-33221.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-22555 | 8.3 HIGH | Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE |
| CVE-2020-25925 | IceWarp WebClient 跨站脚本漏洞 | |
| CVE-2021-21807 | Accusoft ImageGear 输入验证错误漏洞 | |
| CVE-2021-26273 | NinjaRMM 访问控制错误漏洞 | |
| CVE-2021-26274 | NinjaRMM 安全漏洞 | |
| CVE-2021-28931 | Fork CMS 代码问题漏洞 | |
| CVE-2021-31925 | Pexip Infinity 输入验证错误漏洞 | |
| CVE-2021-33215 | CommScope Ruckus IoT Controller 路径遍历漏洞 | |
| CVE-2021-33216 | CommScope Ruckus IoT Controller 安全漏洞 | |
| CVE-2021-33217 | CommScope Ruckus IoT Controller 缓冲区错误漏洞 | |
| CVE-2021-33218 | CommScope Ruckus IoT Controller 信任管理问题漏洞 | |
| CVE-2021-33219 | CommScope Ruckus IoT Controller 信任管理问题漏洞 | |
| CVE-2021-33220 | CommScope Ruckus IoT Controller 信任管理问题漏洞 | |
| CVE-2021-21787 | IOBit Advanced SystemCare 安全漏洞 | |
| CVE-2021-21788 | IOBit Advanced SystemCare 安全漏洞 | |
| CVE-2021-21789 | IOBit Advanced SystemCare 安全漏洞 | |
| CVE-2021-21786 | Iobit IOBit Advanced SystemCare 访问控制错误漏洞 | |
| CVE-2020-23700 | LavaLite 跨站脚本漏洞 | |
| CVE-2020-23702 | PHP-Fusion 跨站脚本漏洞 | |
| CVE-2021-21775 | WebKit WebKitGTK 资源管理错误漏洞 |
Showing top 20 of 42 CVEs. View all on vendor page → →
No comments yet