← Vulnerability feed

Vulnerability record · CVE-2025-67304 · published 19 February 2026

CVE-2025-67304: Commscope ruckus network director hard-coded credentials vulnerability

CCommscope · Ruckus Network Director

In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default configuration, the PostgreSQL service is accessible over the network on TCP port 5432. An attacker can use the hardcoded credentials to authenticate remotely, gaining superuser access to the database. This allows creation of administrative users for the web interface, extraction of password hashes, and execution of arbitrary OS commands.

9.8 CVSS 3.1 Critical EPSS 0.50% · top 59.6% CWE-798 · Hard-coded credentials
9.8CVSS 3.1 base score
0.50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default configuration, the PostgreSQL service is accessible over the network on TCP port 5432. An attacker can use the hardcoded credentials to authenticate remotely, gaining superuser access to the database. This allows creation of administrative users for the web interface, extraction of password hashes, and execution of arbitrary OS commands.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-67304 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-67305Commscope ruckus network director vulnerabilityIn RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These keys are identical across all…EPSS 0.51%8.8CVE-2025-44960Commscope ruckus smartzone firmware os command injection vulnerabilityRUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.EPSS 1.8%8.8CVE-2025-44961Commscope ruckus smartzone firmware os command injection vulnerabilityIn RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.EPSS 2.1%8.8CVE-2025-44957Commscope ruckus smartzone firmware authentication bypass via alternate path vulnerabilityRuckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers.EPSS 0.94%8.8CVE-2025-44955Commscope ruckus network director hard-coded password vulnerabilityRUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password.EPSS 0.46%8.1CVE-2025-44963Commscope ruckus network director vulnerabilityRUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.EPSS 0.64%7.5CVE-2025-44958Commscope ruckus network director vulnerabilityRUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format.EPSS 0.35%4.3CVE-2025-44962Commscope ruckus smartzone firmware vulnerabilityRUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files.EPSS 0.79%

Source: NIST National Vulnerability Database (record CVE-2025-67304), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.