CVE-2021-4474: Ruckus AP CLI Arbitrary File Read Allows Authenticated Remote File Access
Ruckus Access Point products contain an arbitrary file read vulnerability in the command-line interface that allows authenticated remote attackers with administrative privileges to read arbitrary files from the underlying filesystem. Attackers can exploit this vulnerability to access sensitive information including configuration files, credentials, and system data stored on the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-4474?
CVE-2021-4474 has been classified as a high severity vulnerability due to its potential for authenticated remote file access.
How do I fix CVE-2021-4474?
To mitigate CVE-2021-4474, Ruckus Access Point users should apply the latest firmware updates provided by Ruckus.
Who is affected by CVE-2021-4474?
CVE-2021-4474 affects Ruckus Access Point products that have an administrative command-line interface.
What type of vulnerability is CVE-2021-4474?
CVE-2021-4474 is an arbitrary file read vulnerability that allows authenticated users to read any file from the system.
What can an attacker do with CVE-2021-4474?
An attacker exploiting CVE-2021-4474 can gain access to sensitive information by reading arbitrary files from the affected Ruckus Access Point.