CVE-2025-63735: XSS
Published Nov 25, 2025
·Updated
A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp.
Affected Software
2 affected components
Ruckus Unleashed
Ruckuswireless Ruckus Unleashed=200.13.6.1.319
Event History
Nov 25, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-63735?
CVE-2025-63735 has been classified as a medium severity reflected Cross Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-63735?
To fix CVE-2025-63735, update Ruckus Unleashed to the latest version that addresses this XSS vulnerability.
3
What software is affected by CVE-2025-63735?
CVE-2025-63735 affects Ruckus Unleashed version 200.13.6.1.319.
4
What is the impact of CVE-2025-63735?
The impact of CVE-2025-63735 allows attackers to execute arbitrary JavaScript code in the context of the affected user's session.
5
How can CVE-2025-63735 be exploited?
CVE-2025-63735 can be exploited by crafting a malicious URL that includes a specially crafted name parameter targeting the captive-portal endpoint.