PT-2025-28948 · Ruckus · Ruckus Smartzone
Noam Moshe
·
Published
2025-07-08
·
Updated
2025-08-04
·
CVE-2025-44957
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Ruckus SmartZone versions prior to 6.1.2p3 Refresh Build
Description
The software allows authentication bypass via a valid API key and crafted HTTP headers. This issue affects enterprise wireless networks.
Recommendations
Update to version 6.1.2p3 Refresh Build or later.
Fix
Authentication Bypass Using an Alternate Path or Channel
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ruckus Smartzone