RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.
In RUCKUS SmartZone software, a hardcoded SSH private key is part of the firmware image and is identical across all device instances. An attacker who obtains this key — for example, through extraction from a public firmware image — can use it to authenticate as a user with root privileges on any vulnerable device accessible over the network. The attack does not require user interaction or prior authentication, although it involves a certain level of technical complexity (AC:H).
An attacker gains full control of the device with root-level privileges, enabling the reading and modification of configuration, takeover of managed network infrastructure control, and potential lateral movement within the internal network.
RUCKUS SmartZone software must be updated to version 6.1.2p3 Refresh Build or later. Detailed information is available in the official Security Advisory from the manufacturer (CommScope ID 20250710) and in the CERT/CC database (VU#613753). Until the update is applied, it is recommended to restrict SSH interface access to the devices exclusively to trusted management hosts via firewall or ACL lists.
RUCKUS SmartZone (SZ) in all versions prior to 6.1.2p3 Refresh Build, including devices: Commscope Ruckus E510, Commscope Ruckus R560, Commscope Ruckus H320, Commscope Ruckus T310C, and Commscope Ruckus Smartzone 144.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HCommscope Ruckus C110
HWCommscopeall versionsCommscope Ruckus E510
HWCommscopeall versionsCommscope Ruckus H320
HWCommscopeall versionsCommscope Ruckus H350
HWCommscopeall versionsCommscope Ruckus H510
HWCommscopeall versionsCommscope Ruckus M510
HWCommscopeall versionsCommscope Ruckus R320
HWCommscopeall versionsCommscope Ruckus R510
HWCommscopeall versionsCommscope Ruckus R560
HWCommscopeall versionsCommscope Ruckus R610
HWCommscopeall versionsCommscope Ruckus R710
HWCommscopeall versionsCommscope Ruckus R720
HWCommscopeall versionsCommscope Ruckus R730
HWCommscopeall versionsCommscope Ruckus R750
HWCommscopeall versionsCommscope Ruckus Smartzone 100
HWCommscopeall versionsCommscope Ruckus Smartzone 100 D
HWCommscopeall versionsCommscope Ruckus Smartzone 144
HWCommscopeall versionsCommscope Ruckus Smartzone 144 Federal
HWCommscopeall versionsCommscope Ruckus Smartzone 300
HWCommscopeall versionsCommscope Ruckus Smartzone 300 Federal
HWCommscopeall versionsCommscope Ruckus Smartzone Firmware
OSCommscope6.1.27.0.07.1.0< 6.1.2Commscope Ruckus T310c
HWCommscopeall versionsCommscope Ruckus T310d
HWCommscopeall versionsCommscope Ruckus T310n
HWCommscopeall versionsCommscope Ruckus T310s
HWCommscopeall versionsCommscope Ruckus T350se
HWCommscopeall versionsCommscope Ruckus T750
HWCommscopeall versionsCommscope Ruckus T750se
HWCommscopeall versionsCommscope Ruckus Virtual Smartzone
APPCommscopeall versionsCommscope Ruckus Virtual Smartzone Federal
APPCommscopeall versions
Related vulnerabilities
RCE bez uwierzytelnienia w Ruckus Wireless Admin (do wersji 10.4)
Command injection w RUCKUS SmartZone przez pole adresu IP
Path traversal w Ruckus Unleashed/ZoneDirector umożliwia RCE bez uwierzytelnienia
Command injection w CommScope Ruckus — wykonanie komend jako root przez CLI
Format string RCE w CommScope Ruckus Unleashed — nieuwierzytelniony dostęp