Junglewise Threat Intelligence

CVE-2023-25717: Multiple Ruckus Wireless Products CSRF and RCE Vulnerability

CVE-2023-25717 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-05-12

Technologies: Apple Multiple Products. Vendors: Apple.

Executive brief

Ruckus Wireless products contain a vulnerability in the web services component that allows for unauthenticated Remote Code Execution (RCE) and Cross-Site Request Forgery (CSRF). An attacker can execute arbitrary commands via a specially crafted HTTP GET request to the login form.

Affected products

  • Ruckus Wireless ZoneDirector
  • Ruckus Wireless SmartZone
  • Ruckus Wireless Solo AP
  • Ruckus Wireless Wireless Admin through 10.4

Timeline

  • 2023-05-12: disclosed
  • 2023-05-12: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats