A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2023-25717

Multiple Ruckus Wireless Products CSRF and RCE Vulnerability

Published
2023-05-12
Modified
2026-07-31
Sources
cisa-kev

Summary

Ruckus Wireless Access Point (AP) software contains an unspecified vulnerability in the web services component. If the web services component is enabled on the AP, an attacker can perform cross-site request forgery (CSRF) or remote code execution (RCE). This vulnerability impacts Ruckus ZoneDirector, SmartZone, and Solo APs.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.