CVE-2023-49225: XSS
A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector, SmartZone, and AP Solo). If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in the product. As for the affected products/models/versions, see the information provided by the vendor listed under [References] section or the list under [Product Status] section.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49225?
CVE-2023-49225 is classified as a Cross-Site Scripting (XSS) vulnerability with a potential high severity due to the ability to execute arbitrary scripts in the user's web browser.
How do I fix CVE-2023-49225?
To remediate CVE-2023-49225, users should upgrade their Ruckus Access Point firmware to versions beyond 114.0.0.0.6565 for affected models.
Which products are affected by CVE-2023-49225?
CVE-2023-49225 affects various Ruckus Access Point products including R750, R650, R730, T750, and more, specifically those running certain firmware versions.
Can I tell if my Ruckus device is vulnerable to CVE-2023-49225?
You can determine if your Ruckus device is vulnerable by checking its current firmware version against the specifications of CVE-2023-49225.
What happens if CVE-2023-49225 is exploited?
If exploited, CVE-2023-49225 could allow an attacker to inject and execute arbitrary scripts in the context of a logged-in user's web session, compromising user security.