Vulnerability record · CVE-2021-33221 · published 7 July 2021
CVE-2021-33221: CommScope Ruckus IoT Controller exposes unauthenticated API endpoints
CCommscope · Ruckus Iot Controller
CommScope Ruckus IoT Controller 1.7.1.0 and earlier ships API endpoints that lack authentication, mapped to CWE-306 (missing authentication for a critical function). Because these endpoints are reachable without credentials, any network-adjacent party can invoke them, and the record gives no further detail on which functions are exposed.
Description
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, plus a 99th percentile EPSS and public exploit references, makes this an urgent exposure despite the thin description.
What it is
CommScope Ruckus IoT Controller 1.7.1.0 and earlier ships API endpoints that lack authentication, mapped to CWE-306 (missing authentication for a critical function). Because these endpoints are reachable without credentials, any network-adjacent party can invoke them, and the record gives no further detail on which functions are exposed.
Impact
An attacker gains unauthenticated access to critical controller functionality, with CVSS scoring confidentiality, integrity and availability all as high. That implies potential full compromise of the controller rather than a narrow information leak.
Attack surface
The CVSS vector is AV:N/AC:L/PR:N/UI:N, so the endpoints are reachable over the network with no authentication and no user interaction. No other access precondition is stated in the record.
Exploitation
CISA KEV does not list this CVE, but EPSS is 0.56076 (99th percentile) and the references carry an Exploit tag, indicating public exploit material exists. No ransomware usage is documented.
What to do
- Upgrade Ruckus IoT Controller beyond 1.7.1.0 to a vendor-supported fixed release; confirm the fixed version with CommScope since the record does not name one.
- Until patching is possible, restrict network access to the controller's management and API interfaces to trusted management networks only.
- Place the controller behind a firewall or reverse proxy that enforces authentication and blocks direct access to its API endpoints.
- Audit the controller for any internet-facing exposure and remove it, given the unauthenticated attack vector.
- Monitor CommScope advisories for updated guidance, as this record is thin on remediation specifics.
Detection
- Review controller and upstream proxy logs for API requests that arrive without a valid session or authentication header.
- Baseline normal API callers and alert on new or unexpected source IPs hitting controller endpoints.
- Watch for configuration changes, new accounts or device actions originating from the controller that were not initiated by known administrators.
- Hunt for scanning or enumeration traffic against the controller's API paths from untrusted network segments.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://seclists.org/fulldisclosure/2021/May/72 | ExploitMailing ListThird Party Advisory |
| https://korelogic.com/advisories.html | Third Party Advisory |
| http://seclists.org/fulldisclosure/2021/May/72 | ExploitMailing ListThird Party Advisory |
| https://korelogic.com/advisories.html | Third Party Advisory |
Track CVE-2021-33221 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-33221), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.