Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ruckuswireless

First CVE: Oct 16, 2013Active for: 13 yearsTotal CVEs: 46
61.8
VTI Score
TOP TARGET

Ruckuswireless manufactures wireless networking and access-point products that serve enterprise and campus deployments, including controllers and managed switching appliances such as the ZoneDirector series and H-series access points. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and concentrate in command-injection and cross-site-scripting weakness classes, reflecting the command-execution and web-management interfaces endemic to network appliances. The exposure recurs across multiple product generations and firmware versions, underscoring the vendor's broad deployed footprint in the wireless-infrastructure tier where firmware updates can be slow to propagate. Defenders should prioritize inventory and patching of exposed or edge-reachable wireless controllers and access points from this vendor; current exploitation status and exposure counts are shown alongside this summary.

FAUCET AI Generated
46
Total CVEs
More Total CVEs than 98% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
2.2%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Ruckuswireless over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 16, 2013
12 years ago
Most Recent CVE
Nov 25, 2025
241 days ago

Products(138 total)

Top CVEs

Signals from CVEs in this vendor scope (46 CVEs).

46 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-25717CRITICAL
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$
Feb 13, 20239.898YESYES
CVE-2019-19838CRITICAL
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=get-platform-depends to admin/_c
Jan 23, 20209.840NONO
CVE-2020-13916CRITICAL
A stack buffer overflow in webs in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to execute code via an unauthenticated crafted HTTP request. This affe
Jul 28, 20209.831NONO
CVE-2019-19841CRITICAL
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=packet-capture to admin/_cmdstat
Jan 22, 20209.831NONO
CVE-2025-46121CRITICAL
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addSta
Jul 21, 20259.830NONO
CVE-2025-46120CRITICAL
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in
Jul 21, 20259.830NONO
CVE-2020-13917CRITICAL
rkscli in Ruckus Wireless Unleashed through 200.7.10.92 allows a remote attacker to achieve command injection and jailbreak the CLI via a crafted CLI command. This affects C110, E5
Jul 28, 20209.830NONO
CVE-2020-22658CRITICAL
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 2
Jan 20, 20239.829NONO
CVE-2020-22653CRITICAL
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 2
Jan 20, 20239.829NONO
CVE-2019-19839CRITICAL
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=import-category to admin/_cmdsta
Jan 23, 20209.829NONO
View all 46 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products46 CVEs
20%
37%
43%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network45 (97.8%)
Unknown1 (2.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low45 (97.8%)
High0 (0.0%)
Unknown1 (2.2%)
User Interaction
None39 (84.8%)
Unknown1 (2.2%)
Required6 (13.0%)
Privileges Required
Low4 (8.7%)
High5 (10.9%)
None36 (78.3%)
Unknown1 (2.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (46 CVEs).

CISA KEV
1 CVE
2.2% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.2% of CVEs· 95th percentile
ExploitDB
1 CVE
2.2% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ruckuswireless.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ruckuswireless — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ruckuswireless's Products

View all 3 CNAs →

Top CWEs