MEDIUM · 6.1

CVE-2023-49225

A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector, SmartZone, and AP Solo). If this vulnerability is exploited, an arbitrary script may be executed on the web b...

Vulnerability Description

A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector, SmartZone, and AP Solo). If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in the product. As for the affected products/models/versions, see the information provided by the vendor listed under [References] section or the list under [Product Status] section.

CVSS Score

6.1

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
RuckuswirelessR750 Firmware<= 114.0.0.0.6565
RuckuswirelessR750-
RuckuswirelessR650 Firmware<= 114.0.0.0.6565
RuckuswirelessR650-
RuckuswirelessR730 Firmware<= 114.0.0.0.6565
RuckuswirelessR730-
RuckuswirelessT750 Firmware<= 114.0.0.0.6565
RuckuswirelessT750-
RuckuswirelessR510 Firmware<= 114.0.0.0.6565
RuckuswirelessR510-
RuckuswirelessE510 Firmware<= 114.0.0.0.6565
RuckuswirelessE510-
RuckuswirelessC110 Firmware<= 114.0.0.0.6565
RuckuswirelessC110-
RuckuswirelessR320 Firmware<= 114.0.0.0.6565
RuckuswirelessR320-
RuckuswirelessH510 Firmware<= 114.0.0.0.6565
RuckuswirelessH510-
RuckuswirelessH320 Firmware<= 114.0.0.0.6565
RuckuswirelessH320-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-49225?

CVE-2023-49225 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector, SmartZone, and AP Solo). If this vulnerability is exploited, an arbitrary script may be executed on the web b...

How severe is CVE-2023-49225?

CVE-2023-49225 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-49225?

Check the references section above for vendor advisories and patch information. Affected products include: Ruckuswireless R750 Firmware, Ruckuswireless R750, Ruckuswireless R650 Firmware, Ruckuswireless R650, Ruckuswireless R730 Firmware.