TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2023-25717

CRITICALCISA KEV
9.8

Beschreibung

Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring.

CVE Details

CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht2/13/2023
Zuletzt geandert11/3/2025
Quellekev
Honeypot-Sichtungen0

CISA KEV

HerstellerRuckus Wireless
ProduktMultiple Products
SchwachstellennameMultiple Ruckus Wireless Products CSRF and RCE Vulnerability
KEV Aufnahmedatum2023-05-12
Behebungsfrist2023-06-02
Ransomware-NutzungUnknown

Betroffene Produkte

commscope:ruckus_smartzone_firmwareruckuswireless:e510ruckuswireless:h320ruckuswireless:h350ruckuswireless:h500ruckuswireless:h510ruckuswireless:h550ruckuswireless:m510ruckuswireless:m510-jpruckuswireless:p300ruckuswireless:q410ruckuswireless:q710ruckuswireless:q910ruckuswireless:r300ruckuswireless:r310ruckuswireless:r320ruckuswireless:r350ruckuswireless:r500ruckuswireless:r510ruckuswireless:r550ruckuswireless:r560ruckuswireless:r600ruckuswireless:r610ruckuswireless:r650ruckuswireless:r700ruckuswireless:r710ruckuswireless:r720ruckuswireless:r730ruckuswireless:r750ruckuswireless:r760ruckuswireless:r850ruckuswireless:ruckus_wireless_adminruckuswireless:smartzone_apruckuswireless:sz-144ruckuswireless:sz-144-federalruckuswireless:sz100ruckuswireless:sz300ruckuswireless:sz300-federalruckuswireless:t300ruckuswireless:t301nruckuswireless:t301sruckuswireless:t310cruckuswireless:t310druckuswireless:t310nruckuswireless:t310sruckuswireless:t350cruckuswireless:t350druckuswireless:t350seruckuswireless:t504ruckuswireless:t610ruckuswireless:t710ruckuswireless:t710sruckuswireless:t750ruckuswireless:t750seruckuswireless:t811-cmruckuswireless:t811-cm\(non-spf\)ruckuswireless:zd1000ruckuswireless:zd1100ruckuswireless:zd1200ruckuswireless:zd3000ruckuswireless:zd5000

Schwachen (CWE)

CWE-94CWE-94

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.