CRITICAL · 9.9

CVE-2025-44961

In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.

Vulnerability Description

In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.

CVSS Score

9.9

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CommscopeRuckus Smartzone Firmware< 6.1.2
CommscopeRuckus Virtual Smartzone-
CommscopeRuckus Virtual Smartzone-Federal-
CommscopeRuckus C110-
CommscopeRuckus E510-
CommscopeRuckus H320-
CommscopeRuckus H350-
CommscopeRuckus H510-
CommscopeRuckus M510-
CommscopeRuckus R320-
CommscopeRuckus R510-
CommscopeRuckus R560-
CommscopeRuckus R610-
CommscopeRuckus R710-
CommscopeRuckus R720-
CommscopeRuckus R730-
CommscopeRuckus R750-
CommscopeRuckus Smartzone 100-
CommscopeRuckus Smartzone 100-D-
CommscopeRuckus Smartzone 144-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-44961?

CVE-2025-44961 is a vulnerability with a CVSS score of 9.9 (CRITICAL). In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.

How severe is CVE-2025-44961?

CVE-2025-44961 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2025-44961?

Check the references section above for vendor advisories and patch information. Affected products include: Commscope Ruckus Smartzone Firmware, Commscope Ruckus Virtual Smartzone, Commscope Ruckus Virtual Smartzone-Federal, Commscope Ruckus C110, Commscope Ruckus E510.