// SECURITY · THE HONEST VERSION

It still works. Why is that not good enough?

Broken and unpatchable are two different problems that get the same shrug. Here is the un-blurred version - including the three build numbers you can check your own estate against this afternoon.

  • ● Vendor sources linked
  • ● Dates checked 27 July 2026
  • ● Independent — we sell no vendor’s kit

Independent, and dated. 365 Techies is an independent IT firm. We are not an authorised partner, reseller or agent of RUCKUS Networks, Belden, CommScope, Cisco or Cisco Meraki, and we have no access to their support entitlements on your behalf. Every date on this page comes from the vendor’s own published notices, linked in the source column, and was checked on 27 July 2026. Where we could not verify something from a vendor source we say “check with vendor” rather than guess.

Two different problems that get the same shrug

A broken access point is an operational problem. It has a repair, a replacement or a warranty claim at the end of it, and everyone can see something is wrong.

A working access point that can no longer be patched is a different thing entirely: a risk that somebody in the business has to accept knowingly, in full knowledge, ideally in writing. Nothing looks wrong. Everything works. That is precisely the problem.

Vendors and resellers tend to blur these two, because fear sells replacements. So here is the un-blurred version, with the actual numbers you can test yourself against.

Are you patched? Three build numbers

This is the most actionable thing in the whole guide. Check your firmware version against these. If you are below them, you are exposed to a published vulnerability that already has a fix — one you are entitled to and have not applied.

The “am I patched?” test. Below these builds you are exposed to CVE-2025-46120.
SoftwareFixed buildNotes
RUCKUS Unleashed200.15.6.212.27Wi-Fi 5 branch — fixes CVE-2025-46120
RUCKUS Unleashed200.18.7.1.323Current branch — fixes CVE-2025-46120
RUCKUS ZoneDirector10.5.1.0.282Fixes CVE-2025-46120
Vendor advisory
CVE-2025-46120 is a path-traversal flaw enabling unauthenticated remote privilege escalation. The fixes are the three builds above. If your estate is below them, this is a free afternoon’s work with a real security benefit — no new hardware involved. RUCKUS support

The one that is already being exploited

CVE-2023-25717 is reported as an unauthenticated remote code execution flaw in Ruckus Wireless Admin through version 10.4, scoring 9.8 out of 10 — about as bad as these get. It is reported to affect ZoneDirector, SmartZone and standalone access points, with RUCKUS Cloud and Unleashed reported as not impacted.

What makes it different from most vulnerabilities: it was added to the US cybersecurity agency’s Known Exploited Vulnerabilities catalogue and picked up by a botnet. That is not theoretical risk. That is somebody scanning the internet for your controller right now.

Commonly reported — not vendor-confirmed
A sourcing note, because we would rather tell you than pretend: RUCKUS’s own advisory page returned an access error when we tried to read it, so the affected-product detail above comes from vulnerability databases and security press reporting on that advisory, not from the advisory itself. The documented mitigation is disabling the access-point web interface from the command line. If your controller is reachable from the internet and running below version 10.5, treat it as urgent and verify with RUCKUS directly.

“Frozen” is not the same as “abandoned”

Here is the sentence a business actually needs, and it is good news.

Your Wi-Fi 5 estate is probably on a firmware branch that stopped gaining features years ago. That is not the same as being abandoned. That branch is still receiving security fixes — the patch floors above are proof, because they are fixes issued for exactly that old branch.

The day that branch stops receiving security fixes is the day a Wi-Fi 5 estate is genuinely at the end of the road. Until then, patched old kit is a legitimate, defensible position — and anyone telling you otherwise should be asked which specific unpatched vulnerability they are worried about.

If you need to demonstrate a security position to an insurer, a customer or an auditor, that distinction is the whole argument. Ring us and we will help you write it down properly.

// BEFORE YOU RING ANYONE

Walk the site and write down what people actually get

Our free Wi-Fi signal test runs in a browser, needs no sign-up, and scores every room. Ten minutes with it turns “the Wi-Fi is rubbish upstairs” into numbers — which is the difference between a guess and a diagnosis, whoever ends up doing the work. See also our room-by-room method.

Run the free survey

Read next

The full guide

End-of-support dates for every model we could verify, and how to tell whether yours is actually the problem.

When a Meraki licence expires

What actually happens — and what doesn’t.

Cisco Aironet end-of-life

What “last date of support” actually costs you.

Not sure what you're looking at?

Send us a photo of the label on one access point and the make of your controller. We'll tell you what you've got, what its dates are, and whether it's actually your problem — no charge for the answer.

01202 775566 · help@365techies.co.uk · MON–FRI 9AM–5PM