CVE-2025-67305: Commscope Ruckus Network Director
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These keys are identical across all deployments, allowing an attacker with network access to authenticate via SSH without a password. Once authenticated, the attacker can access the PostgreSQL database with superuser privileges, create administrative users for the web interface, and potentially escalate privileges further.
Affected products
- Commscope Ruckus Network Director: before 4.5.0.56 (fixed in 4.5.0.56)
Published 2026-02-19. Last modified 2026-06-17.