what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

CommScope Ruckus IoT Controller Hard-Coded System Passwords

CommScope Ruckus IoT Controller Hard-Coded System Passwords
Posted May 27, 2021
Authored by Jim Becher | Site korelogic.com

Hard-coded, system-level credentials exist on the Ruckus IoT Controller OVA image, and are exposed to attackers who mount the filesystem.

tags | exploit
advisories | CVE-2021-33218
SHA-256 | df1716ceee1afc4991054f7d3e009a901d7b28289e89a2bebb461c0a64b3b1d9

CommScope Ruckus IoT Controller Hard-Coded System Passwords

Change Mirror Download
KL-001-2021-003: CommScope Ruckus IoT Controller Hard-coded System Passwords

Title: CommScope Ruckus IoT Controller Hard-coded System Passwords
Advisory ID: KL-001-2021-003
Publication Date: 2021.05.26
Publication URL: https://korelogic.com/Resources/Advisories/KL-001-2021-003.txt

1. Vulnerability Details

Affected Vendor: CommScope
Affected Product: Ruckus IoT Controller
Affected Version: and earlier
Platform: Linux
CWE Classification: CWE-259: Use of Hard-coded Password
CVE ID: CVE-2021-33218

2. Vulnerability Description

Hard coded, system-level credentials exist on the Ruckus IoT
Controller OVA image, and are exposed to attackers who mount
the filesystem.

3. Technical Description

Ruckus vRIoT server software is available from the software
library at: https://support.ruckuswireless.com/software/

Once the OVA is imported into VirtualBox, a VMDK file is
created. The VMDK file can be mounted and the directory
structure and its contents can be perused. The virtual appliance
contains three system accounts with password hashes. The three
accounts are 'root', 'admin', and 'vriotha'. The 'admin'
account is documented in vendor documentation, but not the
other two accounts.

The password for 'admin' is documented and can be changed
by the user. The password for the 'vriotha' account is
'nplus1user'. The password for the 'vriotha' account
is hardcoded into support scripts. The root hash is still
undergoing password cracking attempts. The 'admin' and 'vriotha'
accounts are restricted in terms of their shell, they do
not drop to typical Unix shell access. The virtual appliance
does not appear to offer a mechanism for changing the default
password from the vendor for the 'root' or 'vriotha' accounts.

4. Mitigation and Remediation Recommendation

The vendor has released an updated firmware ( which
remediates the described vulnerability. Firmware and release
notes are available at:


5. Credit

This vulnerability was discovered by Jim Becher (@jimbecher)
of KoreLogic, Inc.

6. Disclosure Timeline

2021.03.30 - KoreLogic submits vulnerability details to
2021.03.30 - CommScope acknowledges receipt and the intention
to investigate.
2021.04.06 - CommScope notifies KoreLogic that this issue,
along with several others reported by KoreLogic,
will require more than the standard 45 business
day remediation timeline.
2021.04.06 - KoreLogic agrees to extend disclosure embargo if
2021.04.30 - CommScope informs KoreLogic that remediation for
this vulnerability will be available inside of the
standard 45 business day timeline. Requests
KoreLogic acquire CVE number for this
2021.05.14 - 30 business days have elapsed since the
vulnerability was reported to CommScope.
2021.05.17 - CommScope notifies KoreLogic that the patched
version of the firmware will be available the week
of 2021.05.24.
2021.05.19 - KoreLogic requests CVE from MITRE.
2021.05.19 - MITRE issues CVE-2021-33218.
2021.05.25 - CommScope releases firmware and associated
2021.05.26 - KoreLogic public disclosure.

7. Proof of Concept

With the VMDK file mounted at the current working directory:
$ sudo cat etc/shadow



$ egrep '^root|^admin|^vriotha' etc/passwd

scpstr = "vriotha@"+slave_ip+":/tmp/authkey >/dev/null 2>&1"
### Call slave API to create user #####
# HOTST_URL = "https://"+replace_ip+"/service/v1/createUser"
# json_request = {
# "username":"vriotha",
# "password":"nplus1user"

userpwd = 'useradd vriotha ; echo vriotha:nplus1user | chpasswd >/dev/null 2>&1'

scpstr = "vriotha@"+master_ip+":/VRIOT/ha/"

The contents of this advisory are copyright(c) 2021
KoreLogic, Inc. and are licensed under a Creative Commons
Attribution Share-Alike 4.0 (United States) License:

KoreLogic, Inc. is a founder-owned and operated company with a
proven track record of providing security services to entities
ranging from Fortune 500 to small and mid-sized companies. We
are a highly skilled team of senior security consultants doing
by-hand security assessments for the most important networks in
the U.S. and around the world. We are also developers of various
tools and resources aimed at helping the security community.

Our public vulnerability disclosure policy is available at:

Login or Register to add favorites

File Archive:

June 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jun 1st
    18 Files
  • 2
    Jun 2nd
    13 Files
  • 3
    Jun 3rd
    0 Files
  • 4
    Jun 4th
    0 Files
  • 5
    Jun 5th
    32 Files
  • 6
    Jun 6th
    39 Files
  • 7
    Jun 7th
    0 Files
  • 8
    Jun 8th
    0 Files
  • 9
    Jun 9th
    0 Files
  • 10
    Jun 10th
    0 Files
  • 11
    Jun 11th
    0 Files
  • 12
    Jun 12th
    0 Files
  • 13
    Jun 13th
    0 Files
  • 14
    Jun 14th
    0 Files
  • 15
    Jun 15th
    0 Files
  • 16
    Jun 16th
    0 Files
  • 17
    Jun 17th
    0 Files
  • 18
    Jun 18th
    0 Files
  • 19
    Jun 19th
    0 Files
  • 20
    Jun 20th
    0 Files
  • 21
    Jun 21st
    0 Files
  • 22
    Jun 22nd
    0 Files
  • 23
    Jun 23rd
    0 Files
  • 24
    Jun 24th
    0 Files
  • 25
    Jun 25th
    0 Files
  • 26
    Jun 26th
    0 Files
  • 27
    Jun 27th
    0 Files
  • 28
    Jun 28th
    0 Files
  • 29
    Jun 29th
    0 Files
  • 30
    Jun 30th
    0 Files

Top Authors In Last 30 Days

File Tags


packet storm

© 2022 Packet Storm. All rights reserved.

Security Services
Hosting By