← Browse

CVE-2023-25717

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
98.1%
99.9th percentile
CISA KEV
Listed
Added 2023-05-12 · patch by 2023-06-02
Weakness / dates
Published — · modified —

Description

Ruckus Wireless Access Point (AP) software contains an unspecified vulnerability in the web services component. If the web services component is enabled on the AP, an attacker can perform cross-site request forgery (CSRF) or remote code execution (RCE). This vulnerability impacts Ruckus ZoneDirector, SmartZone, and Solo APs.

Official: NVD · CVE.org