Vulnerability Details CVE-2020-8438
Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hidden /forms/nslookupHandler form, as demonstrated by the nslookuptarget=|cat${IFS} substring.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 76.9%
CVSS Severity
CVSS v3 Score 7.2
CVSS v2 Score 9.0
Products affected by CVE-2020-8438
-
cpe:2.3:h:arris:ruckus_zoneflex_r500:-
-
cpe:2.3:o:arris:ruckus_zoneflex_r500_firmware:104.0.0.0.1347