Skip to main content

Ruckus Releases Security Updates

Security updates address an actively exploited vulnerability affecting multiple Ruckus wireless access point devices. 

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security updates address an actively exploited vulnerability affecting multiple Ruckus wireless access point devices. 


Affected platforms

The following platforms are known to be affected:

Threat details

Many Ruckus products are affected

Please see Ruckus advisory for a complete list of products.


Introduction

Ruckus has released security updates to address vulnerabilities in multiple Access Point (AP) devices. The improper handling vulnerability, CVE-2023-25717, could allow a remote, authenticated attacker to send a specially crafted HTTP request to perform remote code execution.

Exploitation in the wild of CVE-2023-25717

Exploitation of CVE-2023-25717 has been reported and a Proof-of-Concept (PoC) code is publicly available.


Remediation advice

Affected organisations are encouraged to review the Ruckus security advisory 20230208: RUCKUS AP Web Vulnerability (RCE/CSRF) and follow the relevant remediation steps. Additional information is available in the FortiGuard Threat Signal Report 35 . 


Definitive source of threat updates


Last edited: 3 May 2023 1:57 pm