CVE-2020-22660: High severity ruckus wireless r310 firmware vulnerability

Published Jan 20, 2023
·
Updated

In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to force bypass Secure Boot failed attempts and run temporarily the previous Backup image.

Affected Software

56 affected components
Ruckuswireless R310 Firmware=10.5.1.0.199
Ruckuswireless R310
Ruckuswireless R500 Firmware=10.5.1.0.199
Ruckuswireless R500
Ruckuswireless R600 Firmware=10.5.1.0.199
Ruckuswireless R600
Ruckuswireless T300 Firmware=10.5.1.0.199
Ruckuswireless T300
Ruckuswireless T301n Firmware=10.5.1.0.199
Ruckuswireless T301n
Ruckuswireless T301s Firmware=10.5.1.0.199
Ruckuswireless T301s
Ruckuswireless Scg200 Firmware<3.6.2.0.795
Ruckuswireless Scg200
Ruckuswireless Sz-100 Firmware<3.6.2.0.795
Ruckuswireless Sz-100
Ruckuswireless Sz-300 Firmware<3.6.2.0.795
Ruckuswireless Sz-300
Ruckuswireless Vsz Firmware<3.6.2.0.795
Ruckuswireless Vsz
Ruckuswireless Zonedirector 1100 Firmware=9.10.2.0.130
Ruckuswireless Zonedirector 1100
Ruckuswireless Zonedirector 1200 Firmware=10.2.1.0.218
Ruckuswireless Zonedirector 1200
Ruckuswireless Zonedirector 3000 Firmware=10.2.1.0.218
Ruckuswireless Zonedirector 3000
Ruckuswireless Zonedirector 5000 Firmware=10.0.1.0.151
Ruckuswireless Zonedirector 5000
All of the following
Ruckuswireless R310 Firmware=10.5.1.0.199
Ruckuswireless R310
All of the following
Ruckuswireless R500 Firmware=10.5.1.0.199
Ruckuswireless R500
All of the following
Ruckuswireless R600 Firmware=10.5.1.0.199
Ruckuswireless R600
All of the following
Ruckuswireless T300 Firmware=10.5.1.0.199
Ruckuswireless T300
All of the following
Ruckuswireless T301n Firmware=10.5.1.0.199
Ruckuswireless T301n
All of the following
Ruckuswireless T301s Firmware=10.5.1.0.199
Ruckuswireless T301s
All of the following
Ruckuswireless Scg200 Firmware<3.6.2.0.795
Ruckuswireless Scg200
All of the following
Ruckuswireless Sz-100 Firmware<3.6.2.0.795
Ruckuswireless Sz-100
All of the following
Ruckuswireless Sz-300 Firmware<3.6.2.0.795
Ruckuswireless Sz-300
All of the following
Ruckuswireless Vsz Firmware<3.6.2.0.795
Ruckuswireless Vsz
All of the following
Ruckuswireless Zonedirector 1100 Firmware=9.10.2.0.130
Ruckuswireless Zonedirector 1100
All of the following
Ruckuswireless Zonedirector 1200 Firmware=10.2.1.0.218
Ruckuswireless Zonedirector 1200
All of the following
Ruckuswireless Zonedirector 3000 Firmware=10.2.1.0.218
Ruckuswireless Zonedirector 3000
All of the following
Ruckuswireless Zonedirector 5000 Firmware=10.0.1.0.151
Ruckuswireless Zonedirector 5000

Event History

Jan 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2020-22660?

CVE-2020-22660 is rated as a medium severity vulnerability due to its potential to allow unauthorized access to affected Ruckus devices.

2

How do I fix CVE-2020-22660?

To fix CVE-2020-22660, upgrade the affected Ruckus firmware to a version that includes the security patches addressing this vulnerability.

3

Which Ruckus products are affected by CVE-2020-22660?

The affected products include R310, R500, R600, T300, T301n, T301s, SCG200, SZ-100, and SZ-300 with specific firmware versions.

4

Is there a workaround for CVE-2020-22660?

No official workarounds have been provided for CVE-2020-22660, so upgrading the firmware is recommended.

5

What kind of attack can CVE-2020-22660 enable?

CVE-2020-22660 could potentially allow an attacker to gain unauthorized access and compromise the affected devices' security.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203