← Vulnerability feed

Vulnerability record · CVE-2021-33221 · published 7 July 2021

CVE-2021-33221: CommScope Ruckus IoT Controller exposes unauthenticated API endpoints

CCommscope · Ruckus Iot Controller

CommScope Ruckus IoT Controller 1.7.1.0 and earlier ships API endpoints that lack authentication, mapped to CWE-306 (missing authentication for a critical function). Because these endpoints are reachable without credentials, any network-adjacent party can invoke them, and the record gives no further detail on which functions are exposed.

9.8 CVSS 3.1 Critical EPSS 56% · top 1.0% CWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score, v2 7.5
56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or user interaction required, plus a 99th percentile EPSS and public exploit references, makes this an urgent exposure despite the thin description.

What it is

CommScope Ruckus IoT Controller 1.7.1.0 and earlier ships API endpoints that lack authentication, mapped to CWE-306 (missing authentication for a critical function). Because these endpoints are reachable without credentials, any network-adjacent party can invoke them, and the record gives no further detail on which functions are exposed.

Impact

An attacker gains unauthenticated access to critical controller functionality, with CVSS scoring confidentiality, integrity and availability all as high. That implies potential full compromise of the controller rather than a narrow information leak.

Attack surface

The CVSS vector is AV:N/AC:L/PR:N/UI:N, so the endpoints are reachable over the network with no authentication and no user interaction. No other access precondition is stated in the record.

Exploitation

CISA KEV does not list this CVE, but EPSS is 0.56076 (99th percentile) and the references carry an Exploit tag, indicating public exploit material exists. No ransomware usage is documented.

What to do

  • Upgrade Ruckus IoT Controller beyond 1.7.1.0 to a vendor-supported fixed release; confirm the fixed version with CommScope since the record does not name one.
  • Until patching is possible, restrict network access to the controller's management and API interfaces to trusted management networks only.
  • Place the controller behind a firewall or reverse proxy that enforces authentication and blocks direct access to its API endpoints.
  • Audit the controller for any internet-facing exposure and remove it, given the unauthenticated attack vector.
  • Monitor CommScope advisories for updated guidance, as this record is thin on remediation specifics.

Detection

  • Review controller and upstream proxy logs for API requests that arrive without a valid session or authentication header.
  • Baseline normal API callers and alert on new or unexpected source IPs hitting controller endpoints.
  • Watch for configuration changes, new accounts or device actions originating from the controller that were not initiated by known administrators.
  • Hunt for scanning or enumeration traffic against the controller's API paths from untrusted network segments.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://seclists.org/fulldisclosure/2021/May/72 ExploitMailing ListThird Party Advisory
https://korelogic.com/advisories.html Third Party Advisory
http://seclists.org/fulldisclosure/2021/May/72 ExploitMailing ListThird Party Advisory
https://korelogic.com/advisories.html Third Party Advisory

Track CVE-2021-33221 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-33218Commscope ruckus iot controller hard-coded credentials vulnerabilityAn issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded System Passwords that provide shell access.EPSS 2.3%9.8CVE-2021-33219Commscope ruckus iot controller hard-coded credentials vulnerabilityAn issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded Web Application Administrator Passwords for the …EPSS 2.2%9.8CVE-2021-33216Commscope ruckus iot controller vulnerabilityAn issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a develope…EPSS 14%8.8CVE-2021-33217Commscope ruckus iot controller out-of-bounds write vulnerabilityAn issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The Web Application allows Arbitrary Read/Write actions by authentica…EPSS 1.4%7.8CVE-2021-33220Commscope ruckus iot controller hard-coded credentials vulnerabilityAn issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. Hard-coded API Keys exist.EPSS 0.25%4.3CVE-2021-33215Commscope ruckus iot controller path traversal vulnerabilityAn issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The API allows Directory Traversal.EPSS 1.2%8.8CVE-2026-67277MikroTik RouterOS btest missing authentication leaks kernel memory and crashes kernelRouterOS accepts a "related" btest connection before the primary session is authenticated, letting an unauthenticated client start an IPv4 UDP test. …KEVEPSS 1.6%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed

Source: NIST National Vulnerability Database (record CVE-2021-33221), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.