CVE-2020-26879
commscope ruckus_vriot Use of Hard-coded Credentials
Record summary
CVE-2020-26879 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the service API by using a backdoor value as the Authorization header.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 28, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ruckus_vriotBrowse commscope / ruckus_vriot | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALRuckus vRioT IoT Controller - Authentication BypassCVSS 9.8
Ruckus vRioT through 1.5.1.0.21 contains an API backdoor caused by a hardcoded token in validate_token.py,letting unauthenticated attackers interact with the API without authentication.
Impact
Unauthenticated attackers can interact with the API without authentication via a hardcoded token, allowing complete control over the IoT controller and connected devices.
Remediation
Update to Ruckus vRioT version 1.5.1.0.22 or later.
Source: ProjectDiscovery