Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-63735-Ruckus-Unleashed-Reflected-XSS — Reflected XSS in Ruckus Unleashed 200.13.6.1.319 via the name parameter. | Kitploit
Tools/GitHubGitHub/huthx/cve-2025-63735-ruckus-unleashed-reflected-xss
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringWeb SecurityPenetration Testing
GitHubhuthx/cve-2025-63735-ruckus-unleashed-reflected-xss

CVE-2025-63735-Ruckus-Unleashed-Reflected-XSS

Reflected XSS in Ruckus Unleashed 200.13.6.1.319 via the name parameter.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
19 months agoNot yet reviewed

CVE-2025-63735 – Reflected XSS in Ruckus Unleashed 200.13.6.1.319

Summary

A reflected cross-site scripting (XSS) vulnerability exists in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp.

Vendor

Ruckus Wireless

Product

Controller-less Systems (RUCKUS Unleashed)

Affected Version

200.13.6.1.319

Vulnerable Endpoint

/selfguestpass/guestAccessSubmit.jsp

Parameter

name

Proof of Concept

https://192.168.1.51/selfguestpass/guestAccessSubmit.jsp?cookie=null&tip=5&name=</p><form> xss

Description

The application reflects unsanitized user-controlled input from the name parameter back into the page response, enabling arbitrary JavaScript execution.

Impact

An attacker can execute JavaScript in the victim’s browser, leading to session hijacking, credential theft, forced redirection, or UI manipulation.

Discoverer

Huthaifa Qashou

References

  • https://www.ruckusnetworks.com/products/network-control-and-management/controller-less/
  • CVE-2025-63735 (MITRE) – Pending publication

Disclosure Timeline

  • Reported to vendor: 24 October 2025
  • CVE reserved: 12 November 2025
  • Public disclosure: 24 November 2025
Download Tool