CVE-2023-25717: Multiple Ruckus Wireless Products CSRF and RCE Vulnerability
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?loginusername=admin&password=password$(curl substring.
Other sources
Ruckus Wireless Access Point (AP) software contains an unspecified vulnerability in the web services component. If the web services component is enabled on the AP, an attacker can perform cross-site request forgery (CSRF) or remote code execution (RCE). This vulnerability impacts Ruckus ZoneDirector, SmartZone, and Solo APs.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If the web services component is enabled on the Ruckus Wireless Access Point (AP), disable/turn off the AP web services to prevent CSRF and remote code execution (RCE).
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25717?
CVE-2023-25717 has been rated as a critical vulnerability due to its potential for remote code execution without authentication.
How do I fix CVE-2023-25717?
To mitigate CVE-2023-25717, it is recommended to upgrade Ruckus Wireless Administration software to a patched version beyond 10.4.
What type of vulnerability is CVE-2023-25717?
CVE-2023-25717 is classified as a remote code execution vulnerability that allows attackers to execute commands on the affected system.
What products are affected by CVE-2023-25717?
CVE-2023-25717 affects multiple Ruckus Wireless products running the administration software version 10.4 and certain SmartZone AP versions.
How does CVE-2023-25717 exploit occur?
The exploitation of CVE-2023-25717 occurs via an unauthenticated HTTP GET request that can be crafted to execute arbitrary commands.