Home

Description

Ruckus Unleashed contains a remote code execution vulnerability in the web-based management interface that allows authenticated remote attackers to execute arbitrary code on the system when gateway mode is enabled. Attackers can exploit this vulnerability by sending specially crafted requests through the management interface to achieve arbitrary code execution on affected systems.

PUBLISHED Reserved 2026-03-23 | Published 2026-03-26 | Updated 2026-03-27 | Assigner VulnCheck




HIGH: 7.7CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

HIGH: 7.5CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)

Product status

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

Default status
affected

unknown (custom)
affected

References

support.ruckuswireless.com/security_bulletins/320 (Ruckus Security Bulletin 20230731) vendor-advisory

www.vulncheck.com/...ashed-authenticated-rce-in-gateway-mode third-party-advisory

cve.org (CVE-2023-7338)

nvd.nist.gov (CVE-2023-7338)

Download JSON