An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The Web Application allows Arbitrary Read/Write actions by authenticated users. The API allows an HTTP POST of arbitrary content into any file on the filesystem as root.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://korelogic.com/advisories.html | third party advisory |
http://seclists.org/fulldisclosure/2021/May/77 | third party advisory mailing list |