CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.
Original NVD Description
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates outside permitted directories, allowing a remote unauthenticated attacker who can upload a template (e.g., via FTP) to escalate privileges and run arbitrary template code on the controller.
Related CVEs
Other vulnerabilities affecting the same vendor(s)