CVE-2025-44954 is a critical vulnerability affecting RUCKUS SmartZone (SZ) versions prior to 6.1.2p3 Refresh Build, where a hardcoded SSH private key for a root-equivalent user account exists. This allows unauthenticated remote attackers to gain full control over affected devices, as indicated by its CVSS score of 9.8 (CRITICAL) and FAUCET Risk Score of 87/100. While there is no known active exploitation (KEV: No) or public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered significant community discussion and media coverage, suggesting high awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.1.2CPE matchmatch criteria | cpe:2.3:o:commscope:ruckus_smartzone_firmware:*:*:*:*:*:*:*:* | ||
6.1.2CPE matchmatch criteria | cpe:2.3:o:commscope:ruckus_smartzone_firmware:6.1.2:-:*:*:*:*:*:* | ||
6.1.2CPE matchmatch criteria | cpe:2.3:o:commscope:ruckus_smartzone_firmware:6.1.2:p2:*:*:*:*:*:* | ||
6.1.2CPE matchmatch criteria | cpe:2.3:o:commscope:ruckus_smartzone_firmware:6.1.2:p3:*:*:*:*:*:* | ||
7.0.0CPE matchmatch criteria | cpe:2.3:o:commscope:ruckus_smartzone_firmware:7.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.