CVE-2023-25717: listed in the CISA KEV catalog CVE-2023-25717 · CVSS 9.8 CRITICAL · EPSS 98% · KEV 2023-05-12
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring.
Is CVE-2023-25717 exploited? Listed in the CISA KEV catalog on 2023-05-12. Federal remediation due 2023-06-02. Past that date by 1170 days. EPSS puts exploitation in the next 30 days at 98%. Public exploit code: none found in monitored sources. Public detection rules exist. Which products and versions are affected? No affected package list recorded here yet.
Is there a patch? No patch identifier recorded here yet.
What PlainSec published about CVE-2023-25717 Primary sources What this record does not say No affected package data. No patch identifier. KEV and EPSS are re-checked daily. Record last updated 2026-08-11.
CVE-2023-25717: listed in the CISA KEV catalog CVE-2023-25717 · CVSS 9.8 CRITICAL · EPSS 98% · KEV 2023-05-12
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring.
Is CVE-2023-25717 exploited? Listed in the CISA KEV catalog on 2023-05-12. Federal remediation due 2023-06-02. Past that date by 1170 days. EPSS puts exploitation in the next 30 days at 98%. Public exploit code: none found in monitored sources. Public detection rules exist. Which products and versions are affected? No affected package list recorded here yet.
Is there a patch? No patch identifier recorded here yet.
What PlainSec published about CVE-2023-25717 Primary sources What this record does not say No affected package data. No patch identifier. KEV and EPSS are re-checked daily. Record last updated 2026-08-11.