#VU24777 OS Command Injection in Ruckus R500 - CVE-2020-8438
Published: January 30, 2020
Ruckus R500
Ruckus Networks
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to insufficient validation of user-supplied input in the hidden "/forms/nslookupHandler" form, as demonstrated by the "nslookuptarget=|cat${IFS}" substring. A remote administrator can execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.