CVE-2025-44960

8.5

RUCKUS · SmartZone (SZ)

RUCKUS SmartZone is vulnerable to OS command injection via a specific API parameter, potentially allowing unauthorized command execution.

Executive summary

A critical OS command injection vulnerability in RUCKUS SmartZone allows authenticated attackers to execute arbitrary commands, posing a severe risk of full system compromise.

Vulnerability

This vulnerability is an OS command injection flaw (CWE-78) triggered through a specific parameter in an API route. The CVSS vector (PR:L) indicates that the attacker must possess low-level privileges to successfully execute this attack.

Business impact

The ability to inject OS commands provides an attacker with the potential to gain full control over the SmartZone controller, leading to unauthorized data access, network disruption, or lateral movement within the management infrastructure. With a CVSS score of 8.5, this high-severity vulnerability represents a significant threat to operational integrity and security, as it facilitates complete system compromise.

Remediation

Immediate Action: Update all affected RUCKUS SmartZone instances to version 6.1.2p3 Refresh Build or later as specified by the vendor security advisory.

Proactive Monitoring: Review administrative API access logs for anomalous, complex, or unusually long string inputs directed at management endpoints.

Compensating Controls: Implement strict network access control lists to limit access to the SmartZone management interface to known, trusted management IP addresses only.

Exploitation status

Public Exploit Available: No confirmed public exploit exists in the provided data.

Analyst recommendation

Given the severity of this command injection vulnerability, organizations must prioritize patching affected SmartZone controllers immediately. Administrators should verify their current version against the 6.1.2p3 Refresh Build threshold and apply the necessary updates to eliminate the potential for unauthorized command execution.

More RUCKUS CVEs

Sources