CVE-2023-25717: Multiple Ruckus Wireless Products CSRF and RCE Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2023-05-12. EPSS: 98.1% chance of exploitation in the next 30 days.
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring.
Affected products
- Commscope Ruckus Smartzone Firmware: before 5.2.1.3 (fixed in 5.2.1.3); version 6.1.0.0.935 only; before 5.2.1.3.1695 (fixed in 5.2.1.3.1695)
- Ruckus Wireless Ruckus Wireless Admin: up to and including 10.4
- Ruckus Wireless Smartzone Ap: before 6.1.0.0.9240 (fixed in 6.1.0.0.9240); before 5.2.2.0.2064 (fixed in 5.2.2.0.2064); before 3.6.2.0.795 (fixed in 3.6.2.0.795); before 6.1.1.0.1274 (fixed in 6.1.1.0.1274)
Published 2023-02-13. Last modified 2026-06-17.