Vulnerability Description
A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector, SmartZone, and AP Solo). If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in the product. As for the affected products/models/versions, see the information provided by the vendor listed under [References] section or the list under [Product Status] section.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ruckuswireless | R750 Firmware | <= 114.0.0.0.6565 |
| Ruckuswireless | R750 | - |
| Ruckuswireless | R650 Firmware | <= 114.0.0.0.6565 |
| Ruckuswireless | R650 | - |
| Ruckuswireless | R730 Firmware | <= 114.0.0.0.6565 |
| Ruckuswireless | R730 | - |
| Ruckuswireless | T750 Firmware | <= 114.0.0.0.6565 |
| Ruckuswireless | T750 | - |
| Ruckuswireless | R510 Firmware | <= 114.0.0.0.6565 |
| Ruckuswireless | R510 | - |
| Ruckuswireless | E510 Firmware | <= 114.0.0.0.6565 |
| Ruckuswireless | E510 | - |
| Ruckuswireless | C110 Firmware | <= 114.0.0.0.6565 |
| Ruckuswireless | C110 | - |
| Ruckuswireless | R320 Firmware | <= 114.0.0.0.6565 |
| Ruckuswireless | R320 | - |
| Ruckuswireless | H510 Firmware | <= 114.0.0.0.6565 |
| Ruckuswireless | H510 | - |
| Ruckuswireless | H320 Firmware | <= 114.0.0.0.6565 |
| Ruckuswireless | H320 | - |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/jp/JVN45891816/Third Party Advisory
- https://support.ruckuswireless.com/security_bulletins/323PatchVendor Advisory
- https://jvn.jp/en/jp/JVN45891816/Third Party Advisory
- https://support.ruckuswireless.com/security_bulletins/323PatchVendor Advisory
FAQ
What is CVE-2023-49225?
CVE-2023-49225 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector, SmartZone, and AP Solo). If this vulnerability is exploited, an arbitrary script may be executed on the web b...
How severe is CVE-2023-49225?
CVE-2023-49225 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-49225?
Check the references section above for vendor advisories and patch information. Affected products include: Ruckuswireless R750 Firmware, Ruckuswireless R750, Ruckuswireless R650 Firmware, Ruckuswireless R650, Ruckuswireless R730 Firmware.