QID 731238

QID 731238: Multiple Ruckus Wireless Products CSRF and RCE Vulnerabilities

Multiple Ruckus Wireless products contain cross-site request forgery (CSRF) and remote code execution (RCE) vulnerabilities due to improper handling of crafted HTTP requests.

Affected Software:
Ruckus Wireless Admin versions 10.4 and prior

QID Detection Logic:
This unauthenticated detection transmits requests to the /forms/doLogin endpoint to verify if a device is vulnerable via a callback.

Depending on the vulnerability being exploited, an unauthenticated remote attacker could exploit these vulnerabilities to conduct CSRF or execute arbitrary code on a targeted system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to refer to the following vendor released advisory for more information pertaining to the vulnerability: CVE-2023-25717 - RUCKUS AP Web Vulnerability (RCE/CSRF)

    CVEs related to QID 731238

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-25717 URL Logo community.ruckuswireless.com/t5/RUCKUS-Self-Help/CVE-2023-25717-RUCKUS-AP-Web-Vulnerability-RCE-CSRF/m-p/58793