Vulnerability Description
RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Commscope | Ruckus Network Director | < 4.5.0.0 |
Related Weaknesses (CWE)
References
- https://claroty.com/team82/disclosure-dashboard/cve-2025-44963Third Party Advisory
- https://kb.cert.org/vuls/id/613753Third Party Advisory
- https://webresources.commscope.com/download/assets/FAQ+Security+Advisory%3A+ID+2Vendor Advisory
- https://www.kb.cert.org/vuls/id/613753
FAQ
What is CVE-2025-44963?
CVE-2025-44963 is a vulnerability with a CVSS score of 9.0 (CRITICAL). RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.
How severe is CVE-2025-44963?
CVE-2025-44963 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-44963?
Check the references section above for vendor advisories and patch information. Affected products include: Commscope Ruckus Network Director.