CVE-2020-22662: Command Injection
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to change and set unauthorized "illegal region code" by remote code Execution command injection which leads to run illegal frequency with maxi output power. Vulnerability allows attacker to create an arbitrary amount of ssid wlans interface per radio which creates overhead over noise (the default max limit is 8 ssid only per radio in solo AP). Vulnerability allows attacker to unlock hidden regions by privilege command injection in WEB GUI.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-22662?
CVE-2020-22662 is classified as a high-severity vulnerability affecting Ruckus wireless firmware versions 10.5.1.0.199 and earlier.
How do I fix CVE-2020-22662?
To fix CVE-2020-22662, upgrade to the latest firmware version above 10.5.1.0.199 for affected Ruckus devices.
Which Ruckus products are affected by CVE-2020-22662?
CVE-2020-22662 affects Ruckus R310, R500, R600, T300, T301n, and T301s devices running specific firmware versions.
Is there a workaround for CVE-2020-22662?
There is no official workaround for CVE-2020-22662; upgrading firmware is the recommended path to mitigate the vulnerability.
What type of vulnerability is CVE-2020-22662?
CVE-2020-22662 is a vulnerability that may allow unauthorized access or control over affected devices.