First published: Wed Jan 29 2020(Updated: )
Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hidden /forms/nslookupHandler form, as demonstrated by the nslookuptarget=|cat${IFS} substring.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Arris Ruckus Zoneflex R500 Firmware | =104.0.0.0.1347 | |
Arris Ruckus Zoneflex R500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Vulnerability CVE-2020-8438 is a security flaw in Ruckus ZoneFlex R500 104.0.0.0.1347 devices that allows an authenticated attacker to execute arbitrary OS commands.
An attacker can exploit CVE-2020-8438 by using the hidden /forms/nslookupHandler form and providing a malicious input with the nslookuptarget=|cat${IFS} substring.
Vulnerability CVE-2020-8438 has a severity rating of critical with a score of 7.2.
Ruckus ZoneFlex R500 104.0.0.0.1347 devices are affected by CVE-2020-8438.
Currently, there is no specific fix available for CVE-2020-8438. It is recommended to follow the vendor's guidance and apply security patches when they become available.