CVE-2025-44954
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9epss 0.7%
exploitation probability
0.7%top 50% of all CVEs
observed exploitation
nono source reports it
In short
RUCKUS SmartZone versions before 6.1.2p3 contain a hardcoded SSH private key embedded in the system that allows anyone with access to the software to log in as a root-level user. This is critical because attackers can gain complete control over the network device without needing valid credentials.
Technical detail
A hardcoded SSH private key exists for a privileged user account in RUCKUS SmartZone prior to 6.1.2p3 Refresh Build. An attacker with network access or who obtains the software binary can extract the private key and establish authenticated SSH sessions with root-equivalent privileges, achieving complete system compromise without authentication bypass techniques.
Summary generated and translated by AI from the official description.
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
RUCKUS · SmartZone