CVE-2020-26879: Commscope Ruckus Vriot

Critical severity, CVSS 9.8. EPSS: 45.1% chance of exploitation in the next 30 days.

Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the service API by using a backdoor value as the Authorization header.

Affected products

  • Commscope Ruckus Vriot: up to and including 1.5.1.0.21

Published 2020-10-26. Last modified 2026-06-17.