CVE-2020-22653
Description
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to exploit the official image signature to force injection unauthorized image signature.
In plain language
AI Act nowThis is a critical weakness in certain Ruckus router/smart network controller firmware that can let an attacker push a fake firmware image without permission; if you run any of the affected Ruckus firmware versions, you should act now.
CVE-2020-22653 is a network-accessible unauthorized firmware/image installation issue (CWE-347) in multiple Ruckus firmware products, where an attacker can abuse the official image signature process to inject an unauthorized signed image, enabling remote code execution/system compromise; the fix is available via firmware updates (not listed in CISA KEV).
What to do now
- Check whether you run any of these devices/products on the listed vulnerable firmware lines: Ruckus R310/R500/R600 (10.5.1.0.199), Ruckus T300/T301n/T301s (10.5.1.0.199), SmartCell Gateway 200 (SCG200 before 3.6.2.0.795), SmartZone 100 (SZ-100 before 3.6.2.0.795), SmartZone 300 (SZ-300 before 3.6.2.0.795), and Virtual SmartZone (vSZ before 3.6.2.0.795).
- If any device is on a vulnerable version, schedule an upgrade to the fixed firmware version: 3.6.2.0.795 (for SCG200, SZ-100, SZ-300, and vSZ).
- For Ruckus R310/R500/R600 and T300/T301n/T301s on 10.5.1.0.199, upgrade to a non-affected release (use the vendor bulletin at the link in your IT ticket to pick the exact target build for your model).
- After upgrading, verify the device reports the updated firmware version and review that no unexpected configuration or management changes were made during the incident window.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- China-Linked APT Expands Arsenal With New ‘Leash’ Backdoorsen-us·SecurityWeek· Exploited Ruckus wireless routers UAT-7810
- China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malwareen·The Hacker News· Incident UAT-7810 malware
- Chinese hackers develop LONGLEASH malware to expand ORB networken-us·BleepingComputer· Incident Ruckus routers UAT-7810
- UAT-7810 continues building ORB networks using new malwareen·Cisco Talos· Research Ruckus wireless routers UAT-7810
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2020-22653 and every CVE in our database. Create a free account — no credit card required.
Create Free Account