Vulnerability Description
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Commscope | Ruckus Smartzone Firmware | < 6.1.2 |
| Commscope | Ruckus Virtual Smartzone | - |
| Commscope | Ruckus Virtual Smartzone-Federal | - |
| Commscope | Ruckus C110 | - |
| Commscope | Ruckus E510 | - |
| Commscope | Ruckus H320 | - |
| Commscope | Ruckus H350 | - |
| Commscope | Ruckus H510 | - |
| Commscope | Ruckus M510 | - |
| Commscope | Ruckus R320 | - |
| Commscope | Ruckus R510 | - |
| Commscope | Ruckus R560 | - |
| Commscope | Ruckus R610 | - |
| Commscope | Ruckus R710 | - |
| Commscope | Ruckus R720 | - |
| Commscope | Ruckus R730 | - |
| Commscope | Ruckus R750 | - |
| Commscope | Ruckus Smartzone 100 | - |
| Commscope | Ruckus Smartzone 100-D | - |
| Commscope | Ruckus Smartzone 144 | - |
Related Weaknesses (CWE)
References
- https://claroty.com/team82/disclosure-dashboard/cve-2025-44960Third Party Advisory
- https://kb.cert.org/vuls/id/613753Third Party AdvisoryUS Government Resource
- https://webresources.commscope.com/download/assets/FAQ+Security+Advisory%3A+ID+2Vendor Advisory
- https://www.kb.cert.org/vuls/id/613753
FAQ
What is CVE-2025-44960?
CVE-2025-44960 is a vulnerability with a CVSS score of 8.5 (HIGH). RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.
How severe is CVE-2025-44960?
CVE-2025-44960 has been rated HIGH with a CVSS base score of 8.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-44960?
Check the references section above for vendor advisories and patch information. Affected products include: Commscope Ruckus Smartzone Firmware, Commscope Ruckus Virtual Smartzone, Commscope Ruckus Virtual Smartzone-Federal, Commscope Ruckus C110, Commscope Ruckus E510.