// SECURITY · THE HONEST VERSION
It still works. Why is that not good enough?
Broken and unpatchable are two different problems that get the same shrug. Here is the un-blurred version - including the three build numbers you can check your own estate against this afternoon.
- ● Vendor sources linked
- ● Dates checked 27 July 2026
- ● Independent — we sell no vendor’s kit
Independent, and dated. 365 Techies is an independent IT firm. We are not an authorised partner, reseller or agent of RUCKUS Networks, Belden, CommScope, Cisco or Cisco Meraki, and we have no access to their support entitlements on your behalf. Every date on this page comes from the vendor’s own published notices, linked in the source column, and was checked on 27 July 2026. Where we could not verify something from a vendor source we say “check with vendor” rather than guess.
Two different problems that get the same shrug
A broken access point is an operational problem. It has a repair, a replacement or a warranty claim at the end of it, and everyone can see something is wrong.
A working access point that can no longer be patched is a different thing entirely: a risk that somebody in the business has to accept knowingly, in full knowledge, ideally in writing. Nothing looks wrong. Everything works. That is precisely the problem.
Vendors and resellers tend to blur these two, because fear sells replacements. So here is the un-blurred version, with the actual numbers you can test yourself against.
Are you patched? Three build numbers
This is the most actionable thing in the whole guide. Check your firmware version against these. If you are below them, you are exposed to a published vulnerability that already has a fix — one you are entitled to and have not applied.
| Software | Fixed build | Notes |
|---|---|---|
| RUCKUS Unleashed | 200.15.6.212.27 | Wi-Fi 5 branch — fixes CVE-2025-46120 |
| RUCKUS Unleashed | 200.18.7.1.323 | Current branch — fixes CVE-2025-46120 |
| RUCKUS ZoneDirector | 10.5.1.0.282 | Fixes CVE-2025-46120 |
The one that is already being exploited
CVE-2023-25717 is reported as an unauthenticated remote code execution flaw in Ruckus Wireless Admin through version 10.4, scoring 9.8 out of 10 — about as bad as these get. It is reported to affect ZoneDirector, SmartZone and standalone access points, with RUCKUS Cloud and Unleashed reported as not impacted.
What makes it different from most vulnerabilities: it was added to the US cybersecurity agency’s Known Exploited Vulnerabilities catalogue and picked up by a botnet. That is not theoretical risk. That is somebody scanning the internet for your controller right now.
“Frozen” is not the same as “abandoned”
Here is the sentence a business actually needs, and it is good news.
Your Wi-Fi 5 estate is probably on a firmware branch that stopped gaining features years ago. That is not the same as being abandoned. That branch is still receiving security fixes — the patch floors above are proof, because they are fixes issued for exactly that old branch.
The day that branch stops receiving security fixes is the day a Wi-Fi 5 estate is genuinely at the end of the road. Until then, patched old kit is a legitimate, defensible position — and anyone telling you otherwise should be asked which specific unpatched vulnerability they are worried about.
If you need to demonstrate a security position to an insurer, a customer or an auditor, that distinction is the whole argument. Ring us and we will help you write it down properly.
// BEFORE YOU RING ANYONE
Walk the site and write down what people actually get
Our free Wi-Fi signal test runs in a browser, needs no sign-up, and scores every room. Ten minutes with it turns “the Wi-Fi is rubbish upstairs” into numbers — which is the difference between a guess and a diagnosis, whoever ends up doing the work. See also our room-by-room method.
Read next
The full guide
End-of-support dates for every model we could verify, and how to tell whether yours is actually the problem.
When a Meraki licence expires
What actually happens — and what doesn’t.
Cisco Aironet end-of-life
What “last date of support” actually costs you.
Not sure what you're looking at?
Send us a photo of the label on one access point and the make of your controller. We'll tell you what you've got, what its dates are, and whether it's actually your problem — no charge for the answer.
01202 775566 · help@365techies.co.uk · MON–FRI 9AM–5PM