PT-2025-28948 · Ruckus · Ruckus Smartzone

Noam Moshe

·

Published

2025-07-08

·

Updated

2025-08-04

·

CVE-2025-44957

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ruckus SmartZone versions prior to 6.1.2p3 Refresh Build
Description The software allows authentication bypass via a valid API key and crafted HTTP headers. This issue affects enterprise wireless networks.
Recommendations Update to version 6.1.2p3 Refresh Build or later.

Fix

Authentication Bypass Using an Alternate Path or Channel

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2026-00179
CVE-2025-44957

Affected Products

Ruckus Smartzone