CVEs (9)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Commscope 1Ruckus Network Director Jun 17, 2026 Feb 19, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These keys are identical across all deployments, allowing an attacker with network access to authenticate...Show more |
1Commscope 1Ruckus Network Director Jun 17, 2026 Feb 19, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default configuration, the PostgreSQL service is accessible over the network o...Show more |
RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key. |
1Commscope 2Ruckus Network Director Ruckus Smartzone FirmwareJun 17, 2026 Aug 4, 2025 N/A· v4 4.3 MEDIUM· v3 N/A· v2 RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files. |
1Commscope 2Ruckus Network Director Ruckus Smartzone FirmwareJun 17, 2026 Aug 4, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user. |
1Commscope 2Ruckus Network Director Ruckus Smartzone FirmwareJun 17, 2026 Aug 4, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route. |
RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format. |
1Commscope 2Ruckus Network Director Ruckus Smartzone FirmwareJun 17, 2026 Aug 4, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers. |
RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password. |