CVE-2025-44957 describes an authentication bypass vulnerability in Ruckus SmartZone (SZ) versions prior to 6.1.2p3 Refresh Build, allowing attackers to gain unauthorized access using a valid API key and specially crafted HTTP headers. This high-severity flaw (CVSS 8.8) is easily exploitable over the network with low complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating a high level of interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.1.2CPE matchmatch criteria | cpe:2.3:o:commscope:ruckus_smartzone_firmware:*:*:*:*:*:*:*:* | ||
6.1.2CPE matchmatch criteria | cpe:2.3:o:commscope:ruckus_smartzone_firmware:6.1.2:-:*:*:*:*:*:* | ||
6.1.2CPE matchmatch criteria | cpe:2.3:o:commscope:ruckus_smartzone_firmware:6.1.2:p2:*:*:*:*:*:* | ||
6.1.2CPE matchmatch criteria | cpe:2.3:o:commscope:ruckus_smartzone_firmware:6.1.2:p3:*:*:*:*:*:* | ||
7.0.0CPE matchmatch criteria | cpe:2.3:o:commscope:ruckus_smartzone_firmware:7.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Reported vulnerabilities in RUCKUS SmartZone and RUCKUS Network Director: CVE-2025-44957, CVE-2025-44962 ...
Jul 10, 2025Reported vulnerabilities in RUCKUS SmartZone and RUCKUS Network Director: CVE-2025-44957, CVE-2025-44962 ...
Jul 10, 2025