Home

Description

Ruckus Access Point products contain an arbitrary file read vulnerability in the command-line interface that allows authenticated remote attackers with administrative privileges to read arbitrary files from the underlying filesystem. Attackers can exploit this vulnerability to access sensitive information including configuration files, credentials, and system data stored on the device.

PUBLISHED Reserved 2026-03-23 | Published 2026-03-26 | Updated 2026-03-26 | Assigner VulnCheck




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

MEDIUM: 4.9CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-552 Files or Directories Accessible to External Parties

Product status

Default status
unaffected

Any version
affected

Default status
affected

Any version
affected

Default status
affected

Any version
affected

Default status
affected

Any version
affected

Default status
affected

Any version
affected

Default status
affected

Any version
affected

Default status
affected

Any version
affected

Default status
affected

Any version
affected

References

support.ruckuswireless.com/security_bulletins/306 (Ruckus Security Bulletin 20210108) vendor-advisory

www.vulncheck.com/...allows-authenticated-remote-file-access third-party-advisory

cve.org (CVE-2021-4474)

nvd.nist.gov (CVE-2021-4474)

Download JSON