VulnerabilityAnalyzed
CVE-2023-25717
Multiple Ruckus Wireless Products CSRF and RCE Vulnerability
KEVCRITICAL 9.8EPSS 98.1%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 2 June 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 98.07% probability · 100th percentile
- CISA KEV
- Listed 12 May 2023 · due 2 June 2023
- Weakness
- CWE-94
- Affected
- ruckuswireless/ruckus wireless admin · ruckuswireless/smartzone ap · commscope/ruckus smartzone firmware
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions or disconnect product if it is end-of-life. https://support.ruckuswireless.com/security_bulletins/315; https://nvd.nist.gov/vuln/detail/CVE-2023-25717
References
- https://cybir.com/2023/cve/proof-of-concept-ruckus-wireless-admin-10-4-unauthenticated-remote-code-execution-csrf-ssrf/Exploit, Third Party Advisory
- https://support.ruckuswireless.com/security_bulletins/315Patch, Product, Vendor Advisory
- https://cybir.com/2023/cve/proof-of-concept-ruckus-wireless-admin-10-4-unauthenticated-remote-code-execution-csrf-ssrf/Exploit, Third Party Advisory
- https://support.ruckuswireless.com/security_bulletins/315Patch, Product, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-25717US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.