CVE Vulnerabilities

CVE-2025-44957

Authentication Bypass Using an Alternate Path or Channel

Published: Aug 04, 2025 | Modified: Nov 03, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

NameVendorStart VersionEnd Version
Ruckus_smartzone_firmwareCommscope*6.1.2 (excluding)
Ruckus_smartzone_firmwareCommscope6.1.2 (including)6.1.2 (including)
Ruckus_smartzone_firmwareCommscope6.1.2-p2 (including)6.1.2-p2 (including)
Ruckus_smartzone_firmwareCommscope6.1.2-p3 (including)6.1.2-p3 (including)
Ruckus_smartzone_firmwareCommscope7.0.0 (including)7.0.0 (including)
Ruckus_smartzone_firmwareCommscope7.1.0 (including)7.1.0 (including)

Potential Mitigations

References