CVE-2023-49225 - CVE House
Back to Database
Status published Unknown CVE-2023-49225

A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector,...

Vulnerability Description

A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector, SmartZone, and AP Solo). If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in the product. As for the affected products/models/versions, see the information provided by the vendor listed under [References] section or the list under [Product Status] section.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-49225

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

CommScope, Inc.

View all reports →

Affected Software

ZoneDirector, SmartZone, AP Solo R750, AP Solo R650, AP Solo R730, AP Solo T750, AP Solo R550, AP Solo R850, AP Solo T750SE, AP Solo R510, AP Solo T310D, AP Solo E510, AP Solo C110, AP Solo R320, AP Solo H510, AP Solo H320, AP Solo T310S, AP Solo T310N, AP Solo T310C, AP Solo T305, AP Solo M510, AP Solo R720, AP Solo R710, AP Solo T710, AP Solo T710s, AP Solo T610, AP Solo T610s, AP Solo R610, AP Solo R310, AP Solo R760, AP Solo R560, AP Solo H550, AP Solo H350, AP Solo T350c, AP Solo T350d, AP Solo T350se, AP Solo R350
Vulnerable Versions:
10.5.1 and earlier , 6.1.1 and earlier , 114.0.0.0.6565 and earlier , 114.0.0.0.5585 and earlier , 110.0.0.0.2014 and earlier , 118.1.0.0.1274 and earlier , 118.1.0.0.1908 and earlier , 116.0.0.0.1506 and earlier , 116.0.0.0.3128 and earlier , 116.0.0.0.1543 and earlier , 116.0.0.0.3136 and earlier , 116.0.0.0.1655 and earlier

Timeline

Official Publish: December 7th, 2023
Last Modified: May 28th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.