CVE Tools

Ruckus-wireless

8 CVEs tracked since 2025. Since Aug 2025, none of them reached CISA KEV.

Ruckus-wireless CVEs per month

Aug 2025 to Aug 2025. Point at a month, or focus the strip and use the arrow keys.
Ruckus-wireless CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2025-0880

Products

The products that kept showing up in Ruckus-wireless's monthly top three, with their CVEs summed over those months.

  1. Ruckus Virtual Smartzone51 month
  2. Ruckus Network Director31 month

Latest CVEs

The 12 most recently published vulnerabilities affecting Ruckus-wireless.

  1. CVE-2021-4474Ruckus AP CLI Arbitrary File Read Allows Authenticated Remote File Access4.9
  2. CVE-2025-6243Уязвимость программного обеспечения для централизованного управления сетевой инфраструктурой Ruckus Network Director, связанная с использованием жестко закодированного криптографического ключа, позволяющая нарушителю обойти существующие ограничения безопасности и повысить свои привилегии8.8
  3. CVE-2025-44955RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password.8.8
  4. CVE-2025-44963RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.9.0
  5. CVE-2025-44958RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format.5.3
  6. CVE-2025-44957Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers.8.5
  7. CVE-2025-44954RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.9.0
  8. CVE-2025-44962RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files.5.0
  9. CVE-2025-44960RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.8.5
  10. CVE-2025-44961In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.9.9
  11. BDU:2024-10300Уязвимость сетевых устройств RUCKUS Wireless Access Points (Ruckus AP), связанная с недостаточной проверкой входных данных, позволяющая нарушителю выполнить произвольный код9.8
  12. CVE-2023-25717Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring.9.8

The record

Peak rank
#108 in Aug 2025
Busiest month shown
Aug 2025, 8 CVEs
Months with a KEV entry
0 since Aug 2025
Monthly snapshots
1 since 2025
Ruckus-wireless's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store