目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-63735 PoC — CommScope Ruckus Unleashed 安全漏洞

来源
关联漏洞
标题: CommScope Ruckus Unleashed 安全漏洞 (CVE-2025-63735)
Description:CommScope Ruckus Unleashed是美国CommScope公司的一款无线路由器。 CommScope Ruckus Unleashed 200.13.6.1.319版本存在安全漏洞,该漏洞源于captive-portal端点selfguestpass/guestAccessSubmit.jsp中参数name处理不当,可能导致反射型跨站脚本攻击。
Description
Reflected XSS in Ruckus Unleashed 200.13.6.1.319 via the name parameter.
介绍
# CVE-2025-63735 – Reflected XSS in Ruckus Unleashed 200.13.6.1.319

## Summary
A reflected cross-site scripting (XSS) vulnerability exists in Ruckus Unleashed 200.13.6.1.319 via the `name` parameter to the captive-portal endpoint `selfguestpass/guestAccessSubmit.jsp`.

## Vendor
Ruckus Wireless

## Product
Controller-less Systems (RUCKUS Unleashed)

## Affected Version
200.13.6.1.319

## Vulnerable Endpoint
`/selfguestpass/guestAccessSubmit.jsp`

## Parameter
`name`

## Proof of Concept
`https://192.168.1.51/selfguestpass/guestAccessSubmit.jsp?cookie=null&tip=5&name=</p><form><iframe &#09;&#10;&#11; src="javascript&#58;alert('huthx')"&#11;&#10;&#09;;>`
![xss](https://github.com/user-attachments/assets/0873ea26-21b2-4012-a31d-89741c700ad4)

## Description
The application reflects unsanitized user-controlled input from the `name` parameter back into the page response, enabling arbitrary JavaScript execution.

## Impact
An attacker can execute JavaScript in the victim’s browser, leading to session hijacking, credential theft, forced redirection, or UI manipulation.

## Discoverer
Huthaifa Qashou

## References
- https://www.ruckusnetworks.com/products/network-control-and-management/controller-less/
- CVE-2025-63735 (MITRE) – Pending publication

## Disclosure Timeline
- Reported to vendor: 24 October 2025
- CVE reserved: 12 November 2025
- Public disclosure: 24 November 2025
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →