{"cvss":9.8,"datePublished":"2023-05-12","dateUpdated":"2023-05-12","description":"Ruckus Wireless Access Point (AP) software contains an unspecified vulnerability in the web services component. If the web services component is enabled on the AP, an attacker can perform cross-site request forgery (CSRF) or remote code execution (RCE). This vulnerability impacts Ruckus ZoneDirector, SmartZone, and Solo APs.","dueDate":"2023-06-02","id":"CVE-2023-25717","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Unknown","notes":"https://support.ruckuswireless.com/security_bulletins/315;  https://nvd.nist.gov/vuln/detail/CVE-2023-25717","product":"Multiple Products","requiredAction":"Apply updates per vendor instructions or disconnect product if it is end-of-life.","severity":"CRITICAL","source":"cisa_known_exploited","title":"Multiple Ruckus Wireless Products CSRF and RCE Vulnerability","vendor":"Ruckus Wireless"}