← Vulnerability feed

Vulnerability record · CVE-2025-44962 · published 4 August 2025

CVE-2025-44962: Commscope ruckus smartzone firmware vulnerability

CCommscope · Ruckus Smartzone Firmware

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files.

4.3 CVSS 3.1 Medium EPSS 0.79% · top 45.5% CWE-24 · CWE-24
4.3CVSS 3.1 base score
0.79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-44962 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-25717Ruckus Wireless Admin unauthenticated command injection RCERuckus Wireless Admin through 10.4 is vulnerable to remote code execution via an unauthenticated HTTP GET request to /forms/doLogin, where the login_…KEVEPSS 98%analysed9.8CVE-2025-67305Commscope ruckus network director vulnerabilityIn RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These keys are identical across all…EPSS 0.51%9.8CVE-2025-67304Commscope ruckus network director hard-coded credentials vulnerabilityIn Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default…EPSS 0.50%9.8CVE-2025-44954Commscope ruckus smartzone firmware vulnerabilityRUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.EPSS 0.75%8.8CVE-2025-44960Commscope ruckus smartzone firmware os command injection vulnerabilityRUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.EPSS 1.8%8.8CVE-2025-44961Commscope ruckus smartzone firmware os command injection vulnerabilityIn RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.EPSS 2.1%8.8CVE-2025-44957Commscope ruckus smartzone firmware authentication bypass via alternate path vulnerabilityRuckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers.EPSS 0.94%8.8CVE-2025-44955Commscope ruckus network director hard-coded password vulnerabilityRUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password.EPSS 0.46%

Source: NIST National Vulnerability Database (record CVE-2025-44962), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.