CVE-2020-26878 is a remote command injection vulnerability affecting Ruckus IoT Module and vRIoT products up to version 1.5.1.0.21. An authenticated attacker can exploit this flaw by submitting a crafted query to the API's /service/v1/createUser endpoint, allowing arbitrary commands to be executed with root privileges. This vulnerability carries a high CVSS score of 8.8, indicating a severe risk with high impact on confidentiality, integrity, and availability, and it is easily exploitable over the network with low privileges. While there is no public exploit code available in Metasploit or ExploitDB, the vulnerability has garnered significant community discussion and media coverage, suggesting awareness and potential for future exploitation, though it is not currently listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.5.1.0.21CPE matchmatch criteria | cpe:2.3:a:commscope:ruckus_vriot:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.