RUCKUS Community Forums are now in READ-ONLY mode while we migrate to a new platform.
You will still be able to read posts and knowledge articles, but will be unable to post new content until Go Live on the new platform Monday August 17.
Lennar Smart Home customers: please contact [email protected] for assistance during the week of August 9-17.
12-07-2023 08:06 AM - edited 02-02-2024 08:54 AM
Hello All,
This is an important security announcement.
| CVE number | CVE-2023-49225 |
| Severity | Medium |
| Workaround | Available |
| Fix | Available |
A vulnerability in the web-based management interface of the RUCKUS AP product line could allow an
unauthenticated, remote attacker to execute a cross-site scripting (XSS) attack against a user that’s
logged on to the interface of an affected device.
A security bulletin was posted by RUCKUS Networks Security team on 28 Nov 2023. Please refer the same from the below link.
Security Advisory: ID 20231128
Fix is already available and customers are advised to upgrade to recommended version.
While you check and plan to upgrade your devices, we strongly recommend you to implement the workaround first, as this will immediately block the possibility of this security vulnerability.
Workaround: This vulnerability can be mitigated by disabling the web services (HTTP and HTTPS) on the AP. This can be done by using the AP CLI commands "set https disable" and "set http disable".
Note: For ZoneDirector and SmartZone APs, the web services components are disabled by default, once AP joins the controller.
Some quick facts:
FAQs
If you have any queries, please use the comment section on this thread and we will be happy to answer and assist.
