CVE-2025-44960: Commscope Ruckus Network Director

High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.

Affected products

  • Commscope Ruckus Network Director: before 4.5.0.51 (fixed in 4.5.0.51)
  • Commscope Ruckus Smartzone Firmware: before 6.1.2 (fixed in 6.1.2); version 6.1.2 only; version 7.0.0 only; version 7.1.0 only

Published 2025-08-04. Last modified 2026-06-17.