VYPR

SmartZone

by Ruckus

CVEs (5)

  • CVE-2025-44961Aug 4, 2025
    risk 0.00cvss epss 0.00

    In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.

  • CVE-2025-44960Aug 4, 2025
    risk 0.00cvss epss 0.00

    RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.

  • CVE-2025-44954Aug 4, 2025
    risk 0.00cvss epss 0.00

    RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.

  • CVE-2025-44957Aug 4, 2025
    risk 0.00cvss epss 0.00

    Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers.

  • CVE-2025-44962Aug 4, 2025
    risk 0.00cvss epss 0.00

    RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files.