PT-2020-16526 · Ruckus · Ruckus Vriot

Published

2020-10-26

·

Updated

2025-06-11

·

CVE-2020-26879

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ruckus vRioT versions 1.5.1.0.21 and earlier
Description The issue concerns an API backdoor that is hardcoded into the validate token.py file. This backdoor allows an unauthenticated attacker to interact with the service API by using a specific backdoor value as the Authorization header.
Recommendations For Ruckus vRioT versions 1.5.1.0.21 and earlier, consider restricting access to the validate token.py file until a patch is available. As a temporary workaround, avoid using the backdoor value in the Authorization header to minimize the risk of exploitation.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2020-26879

Affected Products

Ruckus Vriot