Multiple Ruckus Wireless Products CSRF and RCE
What to do
Apply updates per vendor instructions or disconnect product if it is end-of-life.
CISA deadline 2023-06-02 · passed 3 years 3 months ago · applies to US federal civilian agencies; used elsewhere as a reference SLA
What happened
Ruckus Wireless Access Point (AP) software contains an unspecified vulnerability in the web services component. If the web services component is enabled on the AP, an attacker can perform cross-site request forgery (CSRF) or remote code execution (RCE). This vulnerability impacts Ruckus ZoneDirector, SmartZone, and Solo APs.
Who is affected
Ruckus Wireless Multiple Products. Affected version ranges are listed in the vendor advisory and the NVD entry linked under Sources.
Weakness class: CWE-94.
Timeline
- Added to CISA KEVExploitation in the wild confirmed by CISA
- CISA remediation deadlinepassed 3 years 3 months ago
Sources
- NVD entry for CVE-2023-25717 nvd.nist.gov/vuln/detail/CVE-2023-25717
- CISA Known Exploited Vulnerabilities catalog www.cisa.gov/known-exploited-vulnerabilities-catalog
- support.ruckuswireless.com support.ruckuswireless.com/security_bulletins/315
- nvd.nist.gov nvd.nist.gov/vuln/detail/CVE-2023-25717