CVE-2019-19835 describes a Server-Side Request Forgery (SSRF) vulnerability affecting Ruckus Wireless Unleashed versions through 200.7.10.102.64. This vulnerability allows an unauthenticated remote attacker to trigger a denial of service by manipulating the 'server' attribute within the tools/_rcmdstat.jsp URI. With a CVSS score of 7.5 (High), it presents a low-complexity attack that can be executed over the network without user interaction, leading to high availability impact. There is currently no evidence of active exploitation, nor are there public exploit modules available in Metasploit, Nuclei, or ExploitDB, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 200.7.10.202.94CPE matchmatch criteria | cpe:2.3:o:ruckuswireless:unleashed:*:*:*:*:*:*:*:* | ||
< 9.10.2.0.84CPE matchmatch criteria | cpe:2.3:o:ruckuswireless:zonedirector_1200_firmware:*:*:*:*:*:*:*:* | ||
>= 9.12.0, < 9.12.3.0.136CPE matchmatch criteria | cpe:2.3:o:ruckuswireless:zonedirector_1200_firmware:*:*:*:*:*:*:*:* | ||
>= 9.13.0, < 10.0.1.0.90CPE matchmatch criteria | cpe:2.3:o:ruckuswireless:zonedirector_1200_firmware:*:*:*:*:*:*:*:* | ||
>= 10.1.0, < 10.1.2.0.275CPE matchmatch criteria | cpe:2.3:o:ruckuswireless:zonedirector_1200_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.