CVE-2025-44962
CWE-23漏洞影响Ruckus vSZ设备,允许用户通过相对路径遍历读取敏感文件。由于未提供补丁,建议限制管理访问以降低风险。 2025-7-8 09:31:0 Author: claroty.com(查看原文) 阅读量:6 收藏

High Threat

CWE-23: Relative Path Traversal, Authenticated Arbitrary File Read:

Ruckus vSZ allows for users to download files from an allowed directory, but by hardcoding a directory path, a user could traverse other directory paths with ../ to read sensitive files.

No patches have been supplied by the vendor at this time. To mitigate risk, network administrators should limit access to the wireless management environments that use these affected products, allowing a limited set of trusted users and their authenticated clients to manage Ruckus infrastructure via a secure protocol such as HTTPS or SSH.


文章来源: https://claroty.com/team82/disclosure-dashboard/cve-2025-44962
如有侵权请联系:admin#unsafe.sh