RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.
The vulnerability results from the use of a static, hardcoded secret key value (CWE-321) used to sign JWT (JSON Web Token) tokens. Since the key is identical across all product installations, an attacker who learns this value can independently generate a properly signed JWT token with administrator role. Such a token will be accepted by the application as authentic, allowing the authentication mechanism to be bypassed. The attack requires no privileges, victim interaction, or account access — the only condition is knowledge of the hardcoded key.
An attacker can gain full administrative control over RUCKUS Network Director, which in practice means the ability to modify network configuration, take over managed network devices, and potentially perform further lateral movement within the infrastructure. Due to the scope (S:C), the impact may extend beyond the RND system itself.
Update RUCKUS Network Director to version 4.5 or later as soon as possible, in which the hardcoded JWT key has been replaced with a unique, random secret. Details are available in the official Commscope security notice (Security Advisory ID 20250710) and in the CERT/CC database VULS#613753.
Commscope RUCKUS Network Director (RND) in all versions prior to 4.5.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HCommscope Ruckus Network Director
APPCommscope< 4.5.0.0
Related vulnerabilities
Hardcoded credentials w Ruckus Network Director — dostęp do PostgreSQL i RCE
Hardcoded SSH keys w Commscope RUCKUS Network Director (RCE)
Command injection w RUCKUS SmartZone przez pole adresu IP
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an A...
RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded passw...