Multiple vulnerabilities that remain unpatched in Ruckus Wireless management products could be exploited to fully compromise the network environment they serve. The issues affect Ruckus Wireless Virtual SmartZone (vSZ) and Ruckus Network Director (RND), and range from uauthenticated remote code execution to hardcoded passwords or SSH public and private keys. Ruckus vSZ is a centralized wireless network controller that can manage tens of thousands of Ruckus access points and clients, allowing configuration, monitoring, and controlling large-scale WiFi deployments. Ruckus RND is a management tool for vSZ clusters. The two products are typically used by large organizations and public entities in need of scalable and robust WiFi infrastructure. The vulnerabilities were reported to Carnegie Mellon University’s CERT Coordination Center (CERT/CC) by Noam Moshe, a member of Team82, Claroty's research division. Neither CERT/CC nor Moshe were able to contact Ruckus Wireless (now Ruckus Networks) or its parent company, CommScope, about the security problems, which remain unfixed at the time of publishing. The problems impacting the two Ruckus Networks products received identifiers and are described as follows: Although severity scores have not been calculated, CERT/CC highlights the broad impact of the vulnerabilities, their potential for exploitation, and the possibility to chain them for a more impactful attack. "[The] impact of these vulnerabilities varies from information leakage t...
Ruckus Networks leaves severe flaws unpatched in management devices
BleepingComputer
·Bill Toulas
·Published Jul 9, 2025
·Updated
Affected Software
2 affected components
Ruckus Wireless Virtual SmartZone
Ruckus Wireless Network Director
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses severe unpatched vulnerabilities in Ruckus Wireless management devices that pose a risk to network security.
2
What security implications are discussed?
The vulnerabilities could be exploited to fully compromise the network environment managed by the affected Ruckus products.
3
What products or software are affected?
The affected products include Ruckus Wireless Virtual SmartZone and Ruckus Wireless Network Director.
4
Who is responsible for the vulnerabilities mentioned in the article?
Ruckus Networks is responsible for the unpatched vulnerabilities in their management devices.
5
What steps can users take regarding these vulnerabilities?
Users should monitor for updates from Ruckus Networks and implement security measures to protect their networks until a patch is available.