CVE-2025-69425: Ruckus vRIoT IoT Controller < 3.0.0.0 Hardcoded Tokens RCE
The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2004 running with root privileges. Authentication to this service relies on a hardcoded Time-based One-Time Password (TOTP) secret and an embedded static token. An attacker who extracts these credentials from the appliance or a compromised device can generate valid authentication tokens and execute arbitrary OS commands with root privileges, resulting in complete system compromise.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ruckus vRIoT IoT Controllerto a version that resolves this vulnerability.Fixed in 3.0.0.0 - Compensating control
Block network access to TCP port 2004 (the command execution service) at the firewall/network perimeter to prevent exploitation until the controller is upgraded.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-69425?
CVE-2025-69425 is considered a critical vulnerability due to the potential for command execution with root privileges.
How do I fix CVE-2025-69425?
To address CVE-2025-69425, upgrade the Ruckus vRIoT IoT Controller firmware to version 3.0.0.0 or later.
What systems are affected by CVE-2025-69425?
CVE-2025-69425 affects Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA).
What type of vulnerability is CVE-2025-69425?
CVE-2025-69425 is a command execution vulnerability that exploits a service running on TCP port 2004.
What is the impact of CVE-2025-69425?
The impact of CVE-2025-69425 includes unauthorized command execution, potentially compromising the entire system.