Files
CVEs-PoC/2020/CVE-2020-8438.md
T
2025-09-29 21:09:30 +02:00

727 B

CVE-2020-8438

Description

Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hidden /forms/nslookupHandler form, as demonstrated by the nslookuptarget=|cat${IFS} substring.

POC

Reference

Github

No PoCs found on GitHub currently.