CVE-2019-19836: Ruckus Wireless Unleashed

Critical severity, CVSS 9.8. EPSS: 3.6% chance of exploitation in the next 30 days.

AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote code execution via a POST request that uses tools/_rcmdstat.jsp to write to a specified filename.

Affected products

  • Ruckus Wireless Unleashed: before 200.7.10.202.94 (fixed in 200.7.10.202.94)
  • Ruckus Wireless Zonedirector 1200 Firmware: before 9.10.2.0.84 (fixed in 9.10.2.0.84); from 9.12.0, before 9.12.3.0.136 (fixed in 9.12.3.0.136); from 9.13.0, before 10.0.1.0.90 (fixed in 10.0.1.0.90); from 10.1.0, before 10.1.2.0.275 (fixed in 10.1.2.0.275); from 10.2.0, before 10.2.1.0.147 (fixed in 10.2.1.0.147); from 10.3.0, before 10.3.1.0.21 (fixed in 10.3.1.0.21)

Published 2020-01-22. Last modified 2026-06-17.