Critical severity9.8CISA KEVNVD Advisory· Published Feb 13, 2023· Updated Jun 17, 2026
CVE-2023-25717
CVE-2023-25717
Description
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- cpe:2.3:a:ruckuswireless:ruckus_wireless_admin:*:*:*:*:*:*:*:*Range: <=10.4
cpe:2.3:o:commscope:ruckus_smartzone_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:commscope:ruckus_smartzone_firmware:*:*:*:*:*:*:*:*range: <5.2.1.3
- cpe:2.3:o:commscope:ruckus_smartzone_firmware:6.1.0.0.935:*:*:*:*:*:*:*
- Ruckus/Wireless Admindescription
- Range: <10.4
Patches
Vulnerability mechanics
References
3- support.ruckuswireless.com/security_bulletins/315nvdPatchProductVendor Advisory
- cybir.com/2023/cve/proof-of-concept-ruckus-wireless-admin-10-4-unauthenticated-remote-code-execution-csrf-ssrf/nvdExploitThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
4- China-Linked APT Expands Arsenal With New ‘Leash’ BackdoorsSecurityWeek · Jul 8, 2026
- China-Linked UAT-7810 Expands ORB Network With New LONGLEASH MalwareThe Hacker News · Jul 8, 2026
- Chinese hackers develop LONGLEASH malware to expand ORB networkBleepingComputer · Jul 7, 2026
- UAT-7810 continues building ORB networks using new malwareCisco Talos Intelligence · Jul 7, 2026