CVE-2023-49225

A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector, SmartZone, and AP Solo). If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in the product. As for the affected products/models/versions, see the information provided by the vendor listed under [References] section or the list under [Product Status] section.

Published: 2023-12-07 Last update: 2026-06-17 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2023-49225 is rated Low Risk (36/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.41%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2023-49225

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.32% 0.41% +0.09%
2 2025-11-21 0.19% 0.32% +0.13%
3 2025-11-18 0.19%

Full EPSS history (7 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2023-49225

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.1 3.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:R)
A real person has to do something—click, install, enable—otherwise it doesn’t land.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:L)
Some sensitive info could get out, but not a total data dump.
Integrity (I:L)
Attackers could change some data, but it’s limited—not everything goes.
Availability (A:N)
Service keeps running; no real outage angle.
2.8 2.7 [email protected]
6.1 3.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:R)
A real person has to do something—click, install, enable—otherwise it doesn’t land.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:L)
Some sensitive info could get out, but not a total data dump.
Integrity (I:L)
Attackers could change some data, but it’s limited—not everything goes.
Availability (A:N)
Service keeps running; no real outage angle.
2.8 2.7 134c704f-9b21-4f2e-91b3-4a467353bcc0

Weakness enumeration for CVE-2023-49225

Affected software / configurations for CVE-2023-49225

Vendor Product Version Raw CPE
ruckuswireless r750_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:r750_firmware:*:*:*:*:*:*:*:*
ruckuswireless r650_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:r650_firmware:*:*:*:*:*:*:*:*
ruckuswireless r730_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:r730_firmware:*:*:*:*:*:*:*:*
ruckuswireless t750_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:t750_firmware:*:*:*:*:*:*:*:*
ruckuswireless r510_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:r510_firmware:*:*:*:*:*:*:*:*
ruckuswireless e510_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:e510_firmware:*:*:*:*:*:*:*:*
ruckuswireless c110_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:c110_firmware:*:*:*:*:*:*:*:*
ruckuswireless r320_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:r320_firmware:*:*:*:*:*:*:*:*
ruckuswireless h510_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:h510_firmware:*:*:*:*:*:*:*:*
ruckuswireless h320_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:h320_firmware:*:*:*:*:*:*:*:*
ruckuswireless t305_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:t305_firmware:*:*:*:*:*:*:*:*
ruckuswireless m510_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:m510_firmware:*:*:*:*:*:*:*:*
ruckuswireless r720_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:r720_firmware:*:*:*:*:*:*:*:*
ruckuswireless r710_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:r710_firmware:*:*:*:*:*:*:*:*
ruckuswireless t710_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:t710_firmware:*:*:*:*:*:*:*:*
ruckuswireless t610_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:t610_firmware:*:*:*:*:*:*:*:*
ruckuswireless r610_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:r610_firmware:*:*:*:*:*:*:*:*
ruckuswireless t310d_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:t310d_firmware:*:*:*:*:*:*:*:*
ruckuswireless t310s_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:t310s_firmware:*:*:*:*:*:*:*:*
ruckuswireless t310n_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:t310n_firmware:*:*:*:*:*:*:*:*
ruckuswireless t310c_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:t310c_firmware:*:*:*:*:*:*:*:*
ruckuswireless t710s_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:t710s_firmware:*:*:*:*:*:*:*:*
ruckuswireless t610s_firmware <= 114.0.0.0.6565 cpe:2.3:o:ruckuswireless:t610s_firmware:*:*:*:*:*:*:*:*
ruckuswireless r550_firmware <= 114.0.0.0.5585 cpe:2.3:o:ruckuswireless:r550_firmware:*:*:*:*:*:*:*:*
ruckuswireless r850_firmware <= 114.0.0.0.5585 cpe:2.3:o:ruckuswireless:r850_firmware:*:*:*:*:*:*:*:*
ruckuswireless t750se_firmware <= 114.0.0.0.5585 cpe:2.3:o:ruckuswireless:t750se_firmware:*:*:*:*:*:*:*:*
ruckuswireless r310_firmware <= 110.0.0.0.2014 cpe:2.3:o:ruckuswireless:r310_firmware:*:*:*:*:*:*:*:*
ruckuswireless r760_firmware <= 118.1.0.0.1274 cpe:2.3:o:ruckuswireless:r760_firmware:*:*:*:*:*:*:*:*
ruckuswireless r560_firmware <= 118.1.0.0.1908 cpe:2.3:o:ruckuswireless:r560_firmware:*:*:*:*:*:*:*:*
ruckuswireless h550_firmware <= 116.0.0.0.1506 cpe:2.3:o:ruckuswireless:h550_firmware:*:*:*:*:*:*:*:*
ruckuswireless h350_firmware <= 116.0.0.0.3128 cpe:2.3:o:ruckuswireless:h350_firmware:*:*:*:*:*:*:*:*
ruckuswireless t350c_firmware <= 116.0.0.0.1543 cpe:2.3:o:ruckuswireless:t350c_firmware:*:*:*:*:*:*:*:*
ruckuswireless t350d_firmware <= 116.0.0.0.1543 cpe:2.3:o:ruckuswireless:t350d_firmware:*:*:*:*:*:*:*:*
ruckuswireless t350se_firmware <= 116.0.0.0.3136 cpe:2.3:o:ruckuswireless:t350se_firmware:*:*:*:*:*:*:*:*
ruckuswireless r350_firmware <= 116.0.0.0.1655 cpe:2.3:o:ruckuswireless:r350_firmware:*:*:*:*:*:*:*:*
ruckuswireless smartzone_firmware <= 6.1.1 cpe:2.3:o:ruckuswireless:smartzone_firmware:*:*:*:*:*:*:*:*
ruckuswireless zonedirector_firmware <= 10.5.1 cpe:2.3:o:ruckuswireless:zonedirector_firmware:*:*:*:*:*:*:*:*

References for CVE-2023-49225

cvelogic Threat Intelligence