← Vulnerability feed

Vulnerability record · CVE-2023-25717 · published 13 February 2023

CVE-2023-25717: Ruckus Wireless Admin unauthenticated command injection RCE

Ruckuswireless · Ruckus Wireless Admin

Ruckus Wireless Admin through 10.4 is vulnerable to remote code execution via an unauthenticated HTTP GET request to /forms/doLogin, where the login_username and password parameters are passed to a shell command. The flaw is a code injection issue that lets an attacker run arbitrary commands on the device without credentials. It matters because the affected management interface is network reachable and the vendor has issued a patch.

9.8 CVSS 3.1 Critical CISA KEV since 12 May 2023 EPSS 98% · top 0.1% CWE-94 · Code injection
9.8CVSS 3.1 base score
98%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable RCE with a CVSS score of 9.8, KEV listing and near-maximum EPSS probability makes this an urgent patch-first issue.

What it is

Ruckus Wireless Admin through 10.4 is vulnerable to remote code execution via an unauthenticated HTTP GET request to /forms/doLogin, where the login_username and password parameters are passed to a shell command. The flaw is a code injection issue that lets an attacker run arbitrary commands on the device without credentials. It matters because the affected management interface is network reachable and the vendor has issued a patch.

Impact

An unauthenticated attacker can execute arbitrary commands on the affected Ruckus Wireless Admin device, leading to full compromise of confidentiality, integrity and availability. This can expose credentials, allow persistent access, and enable lateral movement into the managed wireless network.

Attack surface

Reached over the network via HTTP GET to /forms/doLogin on the Ruckus Wireless Admin interface. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

CVE-2023-25717 is listed in CISA KEV with a due date of 2023-06-02, and EPSS shows a 30-day probability of 0.98069 (99.9th percentile). Public proof-of-concept exploit references are present, and CISA notes it was not observed in known ransomware campaigns.

What to do

  • Apply the vendor patch from Ruckus security bulletin 315 as the first action.
  • If the product is end-of-life and cannot be patched, disconnect it from the network per CISA guidance.
  • Restrict access to the Ruckus Wireless Admin interface to trusted management networks only.
  • Monitor and block external or untrusted access to /forms/doLogin and related admin endpoints.
  • Rotate any credentials or secrets that may have been exposed on affected devices.

Detection

  • Search web or proxy logs for HTTP GET requests to /forms/doLogin with shell metacharacters such as $(), backticks, or curl in the login_username or password parameters.
  • Alert on outbound network connections from Ruckus management interfaces to unexpected external hosts.
  • Review device and system logs for unexpected command execution or process creation on Ruckus Wireless Admin hosts.
  • Correlate KEV and EPSS signals with asset inventory to confirm which Ruckus devices remain unpatched.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-25717 to the Known Exploited Vulnerabilities catalog on 12 May 2023 as "Multiple Ruckus Wireless Products CSRF and RCE Vulnerability". Required action: Apply updates per vendor instructions or disconnect product if it is end-of-life. Federal deadline 2 June 2023.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-25717 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-44954Commscope ruckus smartzone firmware vulnerabilityRUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.EPSS 0.75%8.8CVE-2025-44960Commscope ruckus smartzone firmware os command injection vulnerabilityRUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.EPSS 1.8%8.8CVE-2025-44961Commscope ruckus smartzone firmware os command injection vulnerabilityIn RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.EPSS 2.1%8.8CVE-2025-44957Commscope ruckus smartzone firmware authentication bypass via alternate path vulnerabilityRuckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers.EPSS 0.94%4.3CVE-2025-44962Commscope ruckus smartzone firmware vulnerabilityRUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files.EPSS 0.79%8.8CVE-2026-65660Microsoft sharepoint server code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.KEVEPSS 2.1%9.8CVE-2026-60004Gitea diffpatch API code injection enables remote code executionGitea before 1.27.1 allows remote code execution through the diffpatch API by way of Git hook installation. The flaw is a code injection issue (CWE-9…KEVEPSS 24%analysed9.5CVE-2026-72530TrueConf Server sandbox breakout via crafted script code injectionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5 and earlier allow a remote unauthenticated attacker to break o…KEVEPSS 1.7%analysed

Source: NIST National Vulnerability Database (record CVE-2023-25717), CISA KEV, FIRST EPSS (scores of 2026-09-23). This page is refreshed as NVD updates the record.