CVE-2023-7338 HIGH

CVE-2023-7338: Ruckus Unleashed Authenticated RCE in Gateway Mode

Vendor Ruckus Networks
Product RUCKUS H350
Weakness CWE-78
Published March 26, 2026
Last update March 27, 2026

CVSS base score

7.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Ruckus Unleashed contains a remote code execution vulnerability in the web-based management interface that allows authenticated remote attackers to execute arbitrary code on the system when gateway mode is enabled. Attackers can exploit this vulnerability by sending specially crafted requests through the management interface to achieve arbitrary code execution on affected systems.

Key dates

02Disclosure timeline

March 26, 2026 CVE published
March 27, 2026 Record updated