CVE-2023-25717
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
Ruckus Wireless Access Point (AP) software contains an unspecified vulnerability in the web services component. If the web services component is enabled on the AP, an attacker can perform cross-site request forgery (CSRF) or remote code execution (RCE). This vulnerability impacts Ruckus ZoneDirector, SmartZone, and Solo APs.
CISA KEV
- Vendor
- Ruckus Wireless
- Product
- Multiple Products
- Due date
- 2023-06-02
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://support.ruckuswireless.com/security_bulletins/315; https://nvd.nist.gov/vuln/detail/CVE-2023-25717
Exploits
References
Verify integrity in audit chain (admin only). AS-IS.