CVE-2020-26878: OS Command Injection
Published Oct 26, 2020
·Updated
Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoint), injecting arbitrary commands that will be executed as root user via web.py.
Affected Software
2 affected components
CommScope Ruckus Vriot<=1.5.1.0.21
CommScope Ruckus Iot Module
Event History
Oct 26, 2020
CVE Published
via MITRE·07:13 PM
Data Sourced
via MITRE·07:13 PM
Description
Frequently Asked Questions
1
What is CVE-2020-26878?
CVE-2020-26878 is a vulnerability affecting Ruckus through 1.5.1.0.21 that allows remote command injection.
2
How does CVE-2020-26878 work?
CVE-2020-26878 allows an authenticated user to submit a malicious query to the /service/v1/createUser API endpoint, injecting arbitrary commands that will be executed as the root user.
3
What is the severity of CVE-2020-26878?
CVE-2020-26878 has a severity rating of 8.8 (critical).
4
How can I fix CVE-2020-26878?
To fix CVE-2020-26878, Commscope Ruckus Vriot users should upgrade to a version beyond 1.5.1.0.21.
5
Are Commscope Ruckus Iot Module users affected by CVE-2020-26878?
No, Commscope Ruckus Iot Module users are not affected by CVE-2020-26878.