Categories: Cyber Security News

Critical Ruckus Wireless Flaws Expose Enterprise Wi‑Fi Networks

The CERT Coordination Center has disclosed nine critical security vulnerabilities in Ruckus Wireless network management products that could allow attackers to completely compromise enterprise wireless environments.

The vulnerabilities, affecting Virtual SmartZone (vSZ) and Network Director (RND) software, include authentication bypass mechanisms, hardcoded cryptographic keys, and unauthenticated remote code execution capabilities that pose severe risks to organizations using these widely-deployed network management solutions.

Multiple Critical Flaws

The disclosed

Sponsored
vulnerabilities represent a comprehensive security breakdown in Ruckus Wireless products used by schools, hospitals, multi-tenant residences, and smart cities for managing large-scale wireless networks.

Virtual SmartZone, capable of managing up to 10,000 access points and 150,000 connected clients, contains several critical flaws that enable complete system compromise.

Among the most severe vulnerabilities is CVE-2025-44954, which involves unauthenticated remote code execution through hardcoded default SSH keys.

This flaw allows any attacker with access to a Ruckus device to obtain the private key and gain root-level access to vSZ systems.

Additionally, CVE-2025-44957 exposes hardcoded secrets, including JWT signing keys and API keys, enabling authentication bypass and administrator-level access without proper credentials.

The vulnerabilities extend to command injection flaws, with CVE-2025-44960 and CVE-2025-44961 allowing authenticated users to execute arbitrary operating system commands through unsanitized input parameters.

CVE-2025-44962 enables arbitrary file reading through directory traversal attacks, potentially exposing sensitive configuration files and credentials.

Network Director faces similar security issues, including CVE-2025-44963, which involves hardcoded JWT tokens for session validation, and CVE-2025-44955, featuring a weak hardcoded password for privilege escalation.

The platform also stores passwords in recoverable formats using weak encryption keys, as detailed in CVE-2025-44958.

Sponsored

Security Researchers Urge Immediate Mitigation

The vulnerabilities were discovered by Noam Moshe of Claroty Team82, highlighting the extensive security research conducted on these enterprise networking products.

However, the CERT Coordination Center reports they have been unable to reach Ruckus Wireless or their parent company, CommScope, for an official response to the disclosed vulnerabilities.

With no patches currently available from the vendor, CERT recommends implementing immediate mitigation strategies.

Network administrators should isolate wireless management environments using these affected products and restrict access to trusted users only.

The recommendation emphasizes using secure protocols like HTTPS or SSH and limiting network access to prevent exploitation of these critical vulnerabilities.

The disclosure underscores the importance of vendor responsibility in addressing security flaws promptly, particularly for products managing critical network infrastructure.

Organizations using Ruckus Wireless products should implement the recommended mitigations immediately while awaiting vendor patches for these serious security vulnerabilities.

Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant updates

The post Critical Ruckus Wireless Flaws Expose Enterprise Wi‑Fi Networks appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

4,000+ Brand SVG Icons for Developers – theSVG

theSVG is an open-source icon library that provides 4,000+ brand SVG icons as React, Vue,…

46 seconds ago

The $100,000 fee for H-1Bs is causing all sorts of problems

Last fall, President Donald Trump's executive order raising the fee for H-1B visas to $100,000…

16 minutes ago

TheraPlay hosting sensory friendly Easter event April 8

CULLMAN, Ala. – Easter Sunday is approaching! We are less than a month away from all…

32 minutes ago

Brownwood community gathers for ‘Wheels That Move the World’

BROWNWOOD, Texas (KTAB/KRBC) - Families in Brownwood spent part of their spring break getting an…

2 hours ago

MY TAKE: The AI magic is back — whether it endures depends on Amazon’s next moves

I ran an experiment this week that I did not expect to be instructive, and…

3 hours ago

Pluralistic: Corrupt anticorruption (14 Mar 2026)

Today's links Corrupt anticorruption: Notes from a target-rich environment. Hey look at this: Delights to…

4 hours ago

This website uses cookies.