CVE-2020-22662: Command Injection

Published Jan 20, 2023
·
Updated

In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to change and set unauthorized "illegal region code" by remote code Execution command injection which leads to run illegal frequency with maxi output power. Vulnerability allows attacker to create an arbitrary amount of ssid wlans interface per radio which creates overhead over noise (the default max limit is 8 ssid only per radio in solo AP). Vulnerability allows attacker to unlock hidden regions by privilege command injection in WEB GUI.

Affected Software

56 affected components
Ruckuswireless R310 Firmware=10.5.1.0.199
Ruckuswireless R310
Ruckuswireless R500 Firmware=10.5.1.0.199
Ruckuswireless R500
Ruckuswireless R600 Firmware=10.5.1.0.199
Ruckuswireless R600
Ruckuswireless T300 Firmware=10.5.1.0.199
Ruckuswireless T300
Ruckuswireless T301n Firmware=10.5.1.0.199
Ruckuswireless T301n
Ruckuswireless T301s Firmware=10.5.1.0.199
Ruckuswireless T301s
Ruckuswireless Scg200 Firmware<3.6.2.0.795
Ruckuswireless Scg200
Ruckuswireless Sz-100 Firmware<3.6.2.0.795
Ruckuswireless Sz-100
Ruckuswireless Sz-300 Firmware<3.6.2.0.795
Ruckuswireless Sz-300
Ruckuswireless Vsz Firmware<3.6.2.0.795
Ruckuswireless Vsz
Ruckuswireless Zonedirector 1100 Firmware=9.10.2.0.130
Ruckuswireless Zonedirector 1100
Ruckuswireless Zonedirector 1200 Firmware=10.2.1.0.218
Ruckuswireless Zonedirector 1200
Ruckuswireless Zonedirector 3000 Firmware=10.2.1.0.218
Ruckuswireless Zonedirector 3000
Ruckuswireless Zonedirector 5000 Firmware=10.0.1.0.151
Ruckuswireless Zonedirector 5000
All of the following
Ruckuswireless R310 Firmware=10.5.1.0.199
Ruckuswireless R310
All of the following
Ruckuswireless R500 Firmware=10.5.1.0.199
Ruckuswireless R500
All of the following
Ruckuswireless R600 Firmware=10.5.1.0.199
Ruckuswireless R600
All of the following
Ruckuswireless T300 Firmware=10.5.1.0.199
Ruckuswireless T300
All of the following
Ruckuswireless T301n Firmware=10.5.1.0.199
Ruckuswireless T301n
All of the following
Ruckuswireless T301s Firmware=10.5.1.0.199
Ruckuswireless T301s
All of the following
Ruckuswireless Scg200 Firmware<3.6.2.0.795
Ruckuswireless Scg200
All of the following
Ruckuswireless Sz-100 Firmware<3.6.2.0.795
Ruckuswireless Sz-100
All of the following
Ruckuswireless Sz-300 Firmware<3.6.2.0.795
Ruckuswireless Sz-300
All of the following
Ruckuswireless Vsz Firmware<3.6.2.0.795
Ruckuswireless Vsz
All of the following
Ruckuswireless Zonedirector 1100 Firmware=9.10.2.0.130
Ruckuswireless Zonedirector 1100
All of the following
Ruckuswireless Zonedirector 1200 Firmware=10.2.1.0.218
Ruckuswireless Zonedirector 1200
All of the following
Ruckuswireless Zonedirector 3000 Firmware=10.2.1.0.218
Ruckuswireless Zonedirector 3000
All of the following
Ruckuswireless Zonedirector 5000 Firmware=10.0.1.0.151
Ruckuswireless Zonedirector 5000

Event History

Jan 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2020-22662?

CVE-2020-22662 is classified as a high-severity vulnerability affecting Ruckus wireless firmware versions 10.5.1.0.199 and earlier.

2

How do I fix CVE-2020-22662?

To fix CVE-2020-22662, upgrade to the latest firmware version above 10.5.1.0.199 for affected Ruckus devices.

3

Which Ruckus products are affected by CVE-2020-22662?

CVE-2020-22662 affects Ruckus R310, R500, R600, T300, T301n, and T301s devices running specific firmware versions.

4

Is there a workaround for CVE-2020-22662?

There is no official workaround for CVE-2020-22662; upgrading firmware is the recommended path to mitigate the vulnerability.

5

What type of vulnerability is CVE-2020-22662?

CVE-2020-22662 is a vulnerability that may allow unauthorized access or control over affected devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203