CVE-2023-25717
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as… EPSS 98% (100th percentile).
CISA federal remediation date Jun 2 · date passed
Vulnerabilities · 68 days ago
UAT-7810 is moving from using compromised routers for its own traffic to operating a reusable relay layer that other China-linked actors can borrow. Once an edge device is folded into that network, source IP, geolocation, and simple proxy blocking stop telling defenders who is really behind the intrusion.
Cisco Talos says the group is refining LONGLEASH and adding DOGLEASH, JARLEASH, and LeashTest to expand LapDogs across more hardware, including MIPS, ARM, and x64 systems. Talos links the activity to unpatched Ruckus router flaws CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, and ASUS AiCloud CVE-2025-2492, and says UAT-7810 is providing relay infrastructure that UAT-5918 has already used against critical infrastructure targets.
The forward risk is shared infrastructure. Cleaning one router or blocking one relay does not remove the service layer if the device is still being used as a reusable ORB node for later espionage.
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as… EPSS 98% (100th percentile).
CISA federal remediation date Jun 2 · date passed
EPSS 1% (64th percentile).
CVSS 9.8 CRITICAL: in Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus… EPSS 0.6% (44th percentile).
CVSS 9.8 CRITICAL: in Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus… EPSS 0.5% (41st percentile).
5 sources covering this story
China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors
Cisco says the threat actor behind the LapDogs campaign has expanded its SOHO router malware toolkit with LongLeash, DogLeash, and JarLeash backdoors.
China-Linked APT Expands Proxy Network With New Malware
Cisco Talos said China-linked APT UAT-7810 is growing its proxy relay network with new malware
China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
Cisco Talos says UAT-7810 is refining LONGLEASH, DOGLEASH, and JARLEASH to expand the LapDogs ORB network.
Chinese hackers develop LONGLEASH malware to expand ORB network
Chinese hackers tracked as 'UAT-7810' are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers.
UAT-7810 continues building ORB networks using new malware
Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware.
Part of the PlainSec briefing for 2026-07-09