CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-44954

CVSS 9.0v3.1pub. 2025-08-04upd. 2025-08-07

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.

🤖 AI Analysis
How it works

In RUCKUS SmartZone software, a hardcoded SSH private key is part of the firmware image and is identical across all device instances. An attacker who obtains this key — for example, through extraction from a public firmware image — can use it to authenticate as a user with root privileges on any vulnerable device accessible over the network. The attack does not require user interaction or prior authentication, although it involves a certain level of technical complexity (AC:H).

Impact

An attacker gains full control of the device with root-level privileges, enabling the reading and modification of configuration, takeover of managed network infrastructure control, and potential lateral movement within the internal network.

Mitigation & patch

RUCKUS SmartZone software must be updated to version 6.1.2p3 Refresh Build or later. Detailed information is available in the official Security Advisory from the manufacturer (CommScope ID 20250710) and in the CERT/CC database (VU#613753). Until the update is applied, it is recommended to restrict SSH interface access to the devices exclusively to trusted management hosts via firewall or ACL lists.

Who is affected

RUCKUS SmartZone (SZ) in all versions prior to 6.1.2p3 Refresh Build, including devices: Commscope Ruckus E510, Commscope Ruckus R560, Commscope Ruckus H320, Commscope Ruckus T310C, and Commscope Ruckus Smartzone 144.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Commscope Ruckus C110

    HW
    Commscope
    all versions
  • Commscope Ruckus E510

    HW
    Commscope
    all versions
  • Commscope Ruckus H320

    HW
    Commscope
    all versions
  • Commscope Ruckus H350

    HW
    Commscope
    all versions
  • Commscope Ruckus H510

    HW
    Commscope
    all versions
  • Commscope Ruckus M510

    HW
    Commscope
    all versions
  • Commscope Ruckus R320

    HW
    Commscope
    all versions
  • Commscope Ruckus R510

    HW
    Commscope
    all versions
  • Commscope Ruckus R560

    HW
    Commscope
    all versions
  • Commscope Ruckus R610

    HW
    Commscope
    all versions
  • Commscope Ruckus R710

    HW
    Commscope
    all versions
  • Commscope Ruckus R720

    HW
    Commscope
    all versions
  • Commscope Ruckus R730

    HW
    Commscope
    all versions
  • Commscope Ruckus R750

    HW
    Commscope
    all versions
  • Commscope Ruckus Smartzone 100

    HW
    Commscope
    all versions
  • Commscope Ruckus Smartzone 100 D

    HW
    Commscope
    all versions
  • Commscope Ruckus Smartzone 144

    HW
    Commscope
    all versions
  • Commscope Ruckus Smartzone 144 Federal

    HW
    Commscope
    all versions
  • Commscope Ruckus Smartzone 300

    HW
    Commscope
    all versions
  • Commscope Ruckus Smartzone 300 Federal

    HW
    Commscope
    all versions
  • Commscope Ruckus Smartzone Firmware

    OS
    Commscope
    6.1.27.0.07.1.0< 6.1.2
  • Commscope Ruckus T310c

    HW
    Commscope
    all versions
  • Commscope Ruckus T310d

    HW
    Commscope
    all versions
  • Commscope Ruckus T310n

    HW
    Commscope
    all versions
  • Commscope Ruckus T310s

    HW
    Commscope
    all versions
  • Commscope Ruckus T350se

    HW
    Commscope
    all versions
  • Commscope Ruckus T750

    HW
    Commscope
    all versions
  • Commscope Ruckus T750se

    HW
    Commscope
    all versions
  • Commscope Ruckus Virtual Smartzone

    APP
    Commscope
    all versions
  • Commscope Ruckus Virtual Smartzone Federal

    APP
    Commscope
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2023-25717CRITICAL9.8⚠ KEVPL ✓same product

RCE bez uwierzytelnienia w Ruckus Wireless Admin (do wersji 10.4)

CVE-2025-44961CRITICAL9.9PL ✓same product

Command injection w RUCKUS SmartZone przez pole adresu IP

CVE-2025-46120CRITICAL9.8PL ✓same product

Path traversal w Ruckus Unleashed/ZoneDirector umożliwia RCE bez uwierzytelnienia

CVE-2025-46117CRITICAL9.1PL ✓same product

Command injection w CommScope Ruckus — wykonanie komend jako root przez CLI

CVE-2025-46121CRITICAL9.8PL ✓same product

Format string RCE w CommScope Ruckus Unleashed — nieuwierzytelniony dostęp