CVE-2023-25717
Description
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring.
In plain language
AI Act nowCVE-2023-25717 lets an attacker run arbitrary code on Ruckus Wireless Admin systems (up to 10.4) using a simple, no-login web request—so a typical small business running this software should treat it as urgent if the device is reachable.
Unauthenticated remote code execution in Ruckus Wireless Admin through 10.4 via a malicious HTTP GET request (not requiring any login), enabling full compromise when the vulnerable web endpoint is reachable.
What to do now
- Check whether you run “Ruckus Wireless Admin” (and/or “Ruckus SmartZone”) and identify your current version/build.
- If you are on “Ruckus Wireless Admin” version 10.4 or earlier, plan an immediate upgrade to the fixed release.
- If you run “smartzone ap,” upgrade to 6.1.0.0.9240 or newer.
- If you run “ruckus smartzone firmware,” upgrade to 5.2.1.3 or newer.
- If the device can’t be upgraded right away, disconnect it from untrusted networks (especially the public internet) until the fix is applied.
- After updating, review device and web-access logs for suspicious unauthenticated requests around the relevant paths and confirm the system is reachable only from trusted networks.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions or disconnect product if it is end-of-life.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- China-Linked APT Expands Arsenal With New ‘Leash’ Backdoorsen-us·SecurityWeek· Exploited Ruckus wireless routers UAT-7810
- China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malwareen·The Hacker News· Incident UAT-7810 malware
- Chinese hackers develop LONGLEASH malware to expand ORB networken-us·BleepingComputer· Incident Ruckus routers UAT-7810
- UAT-7810 continues building ORB networks using new malwareen·Cisco Talos· Research Ruckus wireless routers UAT-7810
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2023-25717 and every CVE in our database. Create a free account — no credit card required.
Create Free Account