CVE-2020-26878: Commscope Ruckus Vriot
High severity, CVSS 8.8. EPSS: 11.6% chance of exploitation in the next 30 days.
Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoint), injecting arbitrary commands that will be executed as root user via web.py.
Affected products
- Commscope Ruckus Vriot: up to and including 1.5.1.0.21
Published 2020-10-26. Last modified 2026-06-17.