PT-2025-28952 · Ruckus · Ruckus Smartzone
Noam Moshe
·
Published
2025-07-08
·
Updated
2025-08-04
·
CVE-2025-44962
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
RUCKUS SmartZone (SZ) versions prior to 6.1.2p3 Refresh Build
Description
RUCKUS SmartZone (SZ) is susceptible to a directory traversal issue that allows unauthorized access to files. The issue is caused by insufficient validation of user-supplied input, specifically allowing the use of
../ sequences in file paths. This can enable an attacker to read arbitrary files on the system.Recommendations
Update to RUCKUS SmartZone (SZ) version 6.1.2p3 Refresh Build or later.
Fix
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ruckus Smartzone