Remote Code Execution in Ruckus Wireless Unleashed Products
CVE-2019-19841
9.8CRITICAL
What is CVE-2019-19841?
A vulnerability in Ruckus Wireless Unleashed allows remote attackers to execute operating system commands through specially crafted POST requests. By utilizing the 'xcmd=packet-capture' parameter within the 'mac' attribute of the 'admin/_cmdstat.jsp' interface, an attacker can gain unauthorized access to sensitive administrative functions. This flaw highlights significant security concerns for devices running the affected versions, potentially exposing network environments to various attacks.