VYPR

Ruckus Smartzone Firmware

by Commscope

CVEs (6)

  • CVE-2023-25717CriKEVFeb 13, 2023
    risk 0.83cvss 9.8epss 0.98

    Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring.

  • CVE-2025-44961CriAug 4, 2025
    risk 0.65cvss 9.9epss 0.02

    In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.

  • CVE-2025-44954CriAug 4, 2025
    risk 0.59cvss 9.0epss 0.01

    RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.

  • CVE-2025-44960HigAug 4, 2025
    risk 0.55cvss 8.5epss 0.02

    RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.

  • CVE-2025-44957HigAug 4, 2025
    risk 0.55cvss 8.5epss 0.01

    Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers.

  • CVE-2025-44962MedAug 4, 2025
    risk 0.33cvss 5.0epss 0.01

    RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files.