CVE-2023-25717CISA KEVEPSS p99.9%

CVE-2023-25717Multiple Ruckus Wireless Products CSRF and RCE Vulnerability

Ruckus Wireless / Multiple Products

Description

Ruckus Wireless Access Point (AP) software contains an unspecified vulnerability in the web services component. If the web services component is enabled on the AP, an attacker can perform cross-site request forgery (CSRF) or remote code execution (RCE). This vulnerability impacts Ruckus ZoneDirector, SmartZone, and Solo APs.

Scoring

CVSS 9.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS98.07% probability of exploitation · percentile 99.9% · 2026-07-24T12:03:22Z
Last modified2026-06-17

CISA KEV entry

Added to KEV: 2023-05-12

(incoming)1

TypeTargetConfidenceTier
KEVEntryMultiple Ruckus Wireless Products CSRF and RCE Vulnerabilitykev-cve-2023-257170%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-44957
CVE
CVE-2025-46117
CVE
CVE-2025-46120
CVE
Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability
CVE
CVE-2025-46122
CVE
CVE-2025-56752
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.