CVE-2017-6230: Command Injection
Ruckus Networks Solo APs firmware releases R110.x or before and Ruckus Networks SZ managed APs firmware releases R5.x or before contain authenticated Root Command Injection in the web-GUI that could allow authenticated valid users to execute privileged commands on the respective systems.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6230?
CVE-2017-6230 is classified as a critical vulnerability due to the potential for authenticated users to execute arbitrary privileged commands.
How do I fix CVE-2017-6230?
To mitigate CVE-2017-6230, upgrade to firmware versions after R110.x for Solo APs and R5.x for SZ managed APs.
Who is affected by CVE-2017-6230?
CVE-2017-6230 affects users of Ruckus Networks Solo Access Points running firmware R110.x or earlier and Smartzone Managed Access Points with firmware R5.x or earlier.
What type of vulnerability is CVE-2017-6230?
CVE-2017-6230 is an authenticated command injection vulnerability found in the web-GUI of affected Ruckus Networks devices.
Can CVE-2017-6230 be exploited remotely?
CVE-2017-6230 can be exploited by authenticated users on the local network, necessitating valid credentials for exploitation.