CVE-2021-4474: Ruckus AP CLI Arbitrary File Read Allows Authenticated Remote File Access

Published Mar 26, 2026
·
Updated

Ruckus Access Point products contain an arbitrary file read vulnerability in the command-line interface that allows authenticated remote attackers with administrative privileges to read arbitrary files from the underlying filesystem. Attackers can exploit this vulnerability to access sensitive information including configuration files, credentials, and system data stored on the device.

Affected Software

1 affected component
Ruckus Ruckus Access Point

Event History

Mar 26, 2026
CVE Published
via MITRE·07:28 PM
Data Sourced
via MITRE·07:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2021-4474?

CVE-2021-4474 has been classified as a high severity vulnerability due to its potential for authenticated remote file access.

2

How do I fix CVE-2021-4474?

To mitigate CVE-2021-4474, Ruckus Access Point users should apply the latest firmware updates provided by Ruckus.

3

Who is affected by CVE-2021-4474?

CVE-2021-4474 affects Ruckus Access Point products that have an administrative command-line interface.

4

What type of vulnerability is CVE-2021-4474?

CVE-2021-4474 is an arbitrary file read vulnerability that allows authenticated users to read any file from the system.

5

What can an attacker do with CVE-2021-4474?

An attacker exploiting CVE-2021-4474 can gain access to sensitive information by reading arbitrary files from the affected Ruckus Access Point.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203