CVE-2023-25717 is a critical remote code execution (RCE) vulnerability affecting Ruckus Wireless Admin versions through 10.4, allowing unauthenticated attackers to execute arbitrary commands via a crafted HTTP GET request. With a CVSS score of 9.8 (CRITICAL), this flaw is easily exploitable over the network with no authentication required, leading to complete compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, notably by the AndoryuBot botnet for DDoS attacks, and has garnered significant community attention and media coverage, despite lacking public Metasploit or ExploitDB modules.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.4CPE matchmatch criteria | cpe:2.3:a:ruckuswireless:ruckus_wireless_admin:*:*:*:*:*:*:*:* | ||
< 6.1.0.0.9240CPE matchmatch criteria | cpe:2.3:o:ruckuswireless:smartzone_ap:*:*:*:*:*:*:*:* | ||
< 5.2.2.0.2064CPE matchmatch criteria | cpe:2.3:o:ruckuswireless:smartzone_ap:*:*:*:*:*:*:*:* | ||
< 3.6.2.0.795CPE matchmatch criteria | cpe:2.3:o:ruckuswireless:smartzone_ap:*:*:*:*:*:*:*:* | ||
< 6.1.1.0.1274CPE matchmatch criteria | cpe:2.3:o:ruckuswireless:smartzone_ap:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.