RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.
The product uses a hard-coded, unchangeable cryptographic key.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ruckus_network_director | Commscope | * | 4.5.0.0 (excluding) |