CVE-2025-69425: Ruckus Networks Vriot IoT Controller
Critical severity, CVSS 10.0. EPSS: 0.9% chance of exploitation in the next 30 days.
The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2004 running with root privileges. Authentication to this service relies on a hardcoded Time-based One-Time Password (TOTP) secret and an embedded static token. An attacker who extracts these credentials from the appliance or a compromised device can generate valid authentication tokens and execute arbitrary OS commands with root privileges, resulting in complete system compromise.
Affected products
- Ruckus Networks Vriot IoT Controller: from 2.3.0.0 (GA), before 3.0.0.0 (GA) (fixed in 3.0.0.0 (GA)); from 2.3.1.0 (MR), before 3.0.0.0 (GA) (fixed in 3.0.0.0 (GA)); from 2.4.0.0 (GA), before 3.0.0.0 (GA) (fixed in 3.0.0.0 (GA))
Published 2026-01-09. Last modified 2026-06-17.