Ruckuswireless manufactures wireless networking and access-point products that serve enterprise and campus deployments, including controllers and managed switching appliances such as the ZoneDirector series and H-series access points. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and concentrate in command-injection and cross-site-scripting weakness classes, reflecting the command-execution and web-management interfaces endemic to network appliances. The exposure recurs across multiple product generations and firmware versions, underscoring the vendor's broad deployed footprint in the wireless-infrastructure tier where firmware updates can be slow to propagate. Defenders should prioritize inventory and patching of exposed or edge-reachable wireless controllers and access points from this vendor; current exploitation status and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ruckuswireless over time
Signals from CVEs in this vendor scope (46 CVEs).
46 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-25717CRITICAL Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$ | Feb 13, 2023 | 9.8 | 98 | YES | YES |
CVE-2019-19838CRITICAL emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=get-platform-depends to admin/_c | Jan 23, 2020 | 9.8 | 40 | NO | NO |
CVE-2020-13916CRITICAL A stack buffer overflow in webs in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to execute code via an unauthenticated crafted HTTP request. This affe | Jul 28, 2020 | 9.8 | 31 | NO | NO |
CVE-2019-19841CRITICAL emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=packet-capture to admin/_cmdstat | Jan 22, 2020 | 9.8 | 31 | NO | NO |
CVE-2025-46121CRITICAL An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addSta | Jul 21, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-46120CRITICAL An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in | Jul 21, 2025 | 9.8 | 30 | NO | NO |
CVE-2020-13917CRITICAL rkscli in Ruckus Wireless Unleashed through 200.7.10.92 allows a remote attacker to achieve command injection and jailbreak the CLI via a crafted CLI command. This affects C110, E5 | Jul 28, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-22658CRITICAL In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 2 | Jan 20, 2023 | 9.8 | 29 | NO | NO |
CVE-2020-22653CRITICAL In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 2 | Jan 20, 2023 | 9.8 | 29 | NO | NO |
CVE-2019-19839CRITICAL emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=import-category to admin/_cmdsta | Jan 23, 2020 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (46 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ruckuswireless.
Media articles that mention a CVE ID that affects a product developed by Ruckuswireless — matched by CVE ID, not by vendor name.