CVE-2020-22658
Description
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to switch completely to unauthorized image to be Boot as primary verified image.
In plain language
AI Act nowThis is a serious Ruckus router/management firmware flaw that lets an attacker trick the device into booting from an unauthorized software image—so if you run affected Ruckus firmware versions, you should fix it immediately.
CVE-2020-22658 is an attack over the network with no authentication and no user interaction that undermines verified boot by allowing an attacker to replace the primary verified boot image with an unauthorized one, leading to full device control; exploitation has been reported in the wild by UAT-7810.
What to do now
- Check which of your devices (Ruckus R310, R500, R600, T300, T301n, T301s, SmartCell Gateway 200 (SCG200), SZ-100, SZ-300, and vSZ) are running firmware versions at or before the vulnerable releases mentioned for your platform.
- Upgrade SCG200, SZ-100, and SZ-300 (and vSZ) firmware to 3.6.2.0.795 (this is the fixed version explicitly identified).
- If you cannot upgrade right away, isolate affected devices from untrusted networks (especially the internet) until the firmware update is applied.
- After upgrading, re-check the device firmware version to confirm it shows 3.6.2.0.795 on the affected SmartZone/SCG/vSZ systems.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- China-Linked APT Expands Arsenal With New ‘Leash’ Backdoorsen-us·SecurityWeek· Exploited Ruckus wireless routers UAT-7810
- China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malwareen·The Hacker News· Incident UAT-7810 malware
- Chinese hackers develop LONGLEASH malware to expand ORB networken-us·BleepingComputer· Incident Ruckus routers UAT-7810
- UAT-7810 continues building ORB networks using new malwareen·Cisco Talos· Research Ruckus wireless routers UAT-7810
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2020-22658 and every CVE in our database. Create a free account — no credit card required.
Create Free Account