EIP-2026-101963
PRE-CVERuckus IoT Controller (Ruckus vRIoT) 1.5.1.0.21 - Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-101963. PoCs published by Emre SUREN.
AI-analyzed exploit summary This exploit demonstrates a command injection vulnerability in Ruckus IoT Controller (vRIoT) versions <= 1.5.1.0.21, leveraging broken authentication to execute arbitrary commands via the username parameter in a POST request to /service/v1/createUser. It generates a reverse shell payload and uses a hardcoded AES-encrypted token for authentication bypass.
Description
Ruckus IoT Controller (Ruckus vRIoT) 1.5.1.0.21 - Remote Code Execution
Exploits (1)
This exploit demonstrates a command injection vulnerability in Ruckus IoT Controller (vRIoT) versions <= 1.5.1.0.21, leveraging broken authentication to execute arbitrary commands via the username parameter in a POST request to /service/v1/createUser. It generates a reverse shell payload and uses a hardcoded AES-encrypted token for authentication bypass.