A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp.
References
| Link | Resource |
|---|---|
| https://github.com/huthx/CVE-2025-63735-Ruckus-Unleashed-Reflected-XSS | Exploit Third Party Advisory |
| https://www.ruckusnetworks.com/products/network-control-and-management/controller-less/ | Product |
Configurations
History
No history.
Information
Published : 2025-11-25 22:15
Updated : 2026-01-09 02:22
NVD link : CVE-2025-63735
Mitre link : CVE-2025-63735
CVE.ORG link : CVE-2025-63735
JSON object : View
Products Affected
ruckuswireless
- ruckus_unleashed
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
