← Vulnerability feed

Vulnerability record · CVE-2025-67305 · published 19 February 2026

CVE-2025-67305: Commscope ruckus network director vulnerability

CCommscope · Ruckus Network Director

In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These keys are identical across all deployments, allowing an attacker with network access to authenticate via SSH without a password. Once authenticated, the attacker can access the PostgreSQL database with superuser privileges, create administrative users for the web interface, and potentially escalate privileges further.

9.8 CVSS 3.1 Critical EPSS 0.51% · top 58.7% CWE-321 · CWE-321
9.8CVSS 3.1 base score
0.51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These keys are identical across all deployments, allowing an attacker with network access to authenticate via SSH without a password. Once authenticated, the attacker can access the PostgreSQL database with superuser privileges, create administrative users for the web interface, and potentially escalate privileges further.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-67305 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-67304Commscope ruckus network director hard-coded credentials vulnerabilityIn Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default…EPSS 0.50%8.8CVE-2025-44960Commscope ruckus smartzone firmware os command injection vulnerabilityRUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.EPSS 1.8%8.8CVE-2025-44961Commscope ruckus smartzone firmware os command injection vulnerabilityIn RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.EPSS 2.1%8.8CVE-2025-44957Commscope ruckus smartzone firmware authentication bypass via alternate path vulnerabilityRuckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers.EPSS 0.94%8.8CVE-2025-44955Commscope ruckus network director hard-coded password vulnerabilityRUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password.EPSS 0.46%8.1CVE-2025-44963Commscope ruckus network director vulnerabilityRUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.EPSS 0.64%7.5CVE-2025-44958Commscope ruckus network director vulnerabilityRUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format.EPSS 0.35%4.3CVE-2025-44962Commscope ruckus smartzone firmware vulnerabilityRUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files.EPSS 0.79%

Source: NIST National Vulnerability Database (record CVE-2025-67305), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.