VDB
CVE-2025-44960
CVE-2025-44960
PUBLISHED
CVSS 8.5 HIGH
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.
EPSS 0.51% · 66.9th percentile
Risk Scores
CVSS 3.1
8.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.51%
66.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| commscope | ruckus_network_director | 0 |
| RUCKUS | SmartZone | 0 |
| commscope | ruckus_smartzone_firmware | 6.1.2, 7.0.0, 0 |
Timeline
- Jul 8, 2025 PoC Published
- Jul 14, 2025 PoC Published
- Aug 4, 2025 CVE Published
- Aug 4, 2025 PoC Published
- Aug 5, 2025 EPSS Score
- Aug 14, 2025 EPSS Score
- Aug 22, 2025 EPSS Score
- Aug 31, 2025 EPSS Score
- Sep 8, 2025 EPSS Score
- Sep 17, 2025 EPSS Score
- Sep 25, 2025 EPSS Score
- Oct 4, 2025 EPSS Score
References
- https://kb.cert.org/vuls/id/613753 url
- https://webresources.commscope.com/download/assets/FAQ+Security+Advisory%3A+ID+20250710/225f44ac3bd311f095821adcaa92e24e url
- https://claroty.com/team82/disclosure-dashboard/cve-2025-44960 url
- https://www.kb.cert.org/vuls/id/613753 url
- https://nvd.nist.gov/vuln/detail/CVE-2025-44960 advisory