Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Commscope

First CVE: Jun 19, 2014Active for: 12 yearsTotal CVEs: 68
68.4
VTI Score
TOP TARGET

CommScope's vulnerability profile centers on a broad portfolio of wireless networking and infrastructure products, particularly Ruckus-branded access points, controllers, and switching systems deployed across enterprise campuses and service-provider networks. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the command-injection, credential-handling, and web-interface weaknesses that recur across its product line. The exposure concentrates in flagship products such as the Ruckus R560, R610, H320, C110, and M510 series and is characterized by command-injection flaws, cross-site request forgery, hard-coded credentials, and sensitive-information exposure that are typical of embedded network appliances with web management interfaces. Defenders should treat CommScope wireless and switching infrastructure as a high-priority patching target given the critical-severity skew and assume that internet-reachable management ports and default credential exposure pose immediate risk. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
68
Total CVEs
More Total CVEs than 99% of tracked vendors
0.1
Avg CVEs / Product / Year
Bottom 1%
8.4
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
1.5%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Commscope over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 19, 2014
12 years ago
Most Recent CVE
Feb 19, 2026
155 days ago

Products(96 total)

Top CVEs

Signals from CVEs in this vendor scope (68 CVEs).

68 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-25717CRITICAL
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$
Feb 13, 20239.898YESYES
CVE-2021-33221CRITICAL
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints.
Jul 7, 20219.871NOYES
CVE-2020-26879CRITICAL
Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the service API by using a backdoor valu
Oct 26, 20209.866NOYES
CVE-2022-45701HIGH
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
Feb 17, 20238.865NOYES
CVE-2021-33216CRITICAL
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a developer account.
Jul 7, 20219.846NOYES
CVE-2022-27002CRITICAL
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、ddns_host parameters. This vulnerability
Mar 15, 20229.835NONO
CVE-2022-26998CRITICAL
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin parameter. This vulnerability allows attackers
Mar 15, 20229.833NONO
CVE-2020-26878HIGH
Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoint), injecting arbitrary comman
Oct 26, 20208.833NONO
CVE-2025-44961HIGH
In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.
Aug 4, 20258.832NONO
CVE-2022-27001CRITICAL
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter. This vulnerability allows attackers to execute ar
Mar 15, 20229.832NONO
View all 68 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products68 CVEs
21%
38%
41%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (1.5%)
Network63 (92.6%)
Unknown1 (1.5%)
Physical0 (0.0%)
Adjacent Network3 (4.4%)
Attack Complexity
Low59 (86.8%)
High8 (11.8%)
Unknown1 (1.5%)
User Interaction
None57 (83.8%)
Unknown1 (1.5%)
Required10 (14.7%)
Privileges Required
Low13 (19.1%)
High5 (7.4%)
None49 (72.1%)
Unknown1 (1.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (68 CVEs).

CISA KEV
1 CVE
1.5% of CVEs· 99th percentile
Metasploit
1 CVE
1.5% of CVEs· 97th percentile
Nuclei
3 CVEs
4.4% of CVEs· 95th percentile
ExploitDB
4 CVEs
5.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Commscope.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Commscope — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Commscope's Products

View all 4 CNAs →

Top CWEs