CommScope Ruckus IoT Controller 1.7.1.0 Unauthenticated API Endpoints

Three API endpoints for the IoT Controller are accessible without authentication. Two of the endpoints result in information leakage and consumption of computing/storage resources. The third API endpoint that does not require authentication allows for a factory reset of the IoT Controller.

Leave a Reply