CVE-2025-44963: Critical severity Ruckus Network Director vulnerability
Published Aug 4, 2025
·Updated
RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.
Affected Software
2 affected components
Ruckus Network Director<4.5
CommScope Ruckus Network Director<4.5.0.0
Event History
Aug 4, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-44963?
CVE-2025-44963 is considered a high severity vulnerability due to its potential to allow an attacker to spoof administrator JWTs.
2
How do I fix CVE-2025-44963?
To address CVE-2025-44963, update RUCKUS Network Director to version 4.5 or later.
3
What attack vector is associated with CVE-2025-44963?
CVE-2025-44963 allows an attacker to leverage a hardcoded secret key for spoofing legitimate administrator tokens.
4
Which software versions are affected by CVE-2025-44963?
CVE-2025-44963 affects RUCKUS Network Director versions prior to 4.5.
5
Is CVE-2025-44963 publicly known?
Yes, CVE-2025-44963 has been publicly disclosed and documented in various security advisories.