8.8

CVE-2025-44960

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.

Data is provided by the National Vulnerability Database (NVD)
CommscopeRuckus Smartzone Firmware Version < 6.1.2
   CommscopeRuckus Virtual Smartzone Version-
   CommscopeRuckus Virtual Smartzone-federal Version-
   CommscopeRuckus C110 Version-
   CommscopeRuckus E510 Version-
   CommscopeRuckus H320 Version-
   CommscopeRuckus H350 Version-
   CommscopeRuckus H510 Version-
   CommscopeRuckus M510 Version-
   CommscopeRuckus R320 Version-
   CommscopeRuckus R510 Version-
   CommscopeRuckus R560 Version-
   CommscopeRuckus R610 Version-
   CommscopeRuckus R710 Version-
   CommscopeRuckus R720 Version-
   CommscopeRuckus R730 Version-
   CommscopeRuckus R750 Version-
   CommscopeRuckus Smartzone 100 Version-
   CommscopeRuckus Smartzone 100-d Version-
   CommscopeRuckus Smartzone 144 Version-
   CommscopeRuckus Smartzone 144-federal Version-
   CommscopeRuckus Smartzone 300 Version-
   CommscopeRuckus Smartzone 300-federal Version-
   CommscopeRuckus T310c Version-
   CommscopeRuckus T310d Version-
   CommscopeRuckus T310n Version-
   CommscopeRuckus T310s Version-
   CommscopeRuckus T350se Version-
   CommscopeRuckus T750 Version-
   CommscopeRuckus T750se Version-
CommscopeRuckus Smartzone Firmware Version6.1.2 Update-
   CommscopeRuckus Virtual Smartzone Version-
   CommscopeRuckus Virtual Smartzone-federal Version-
   CommscopeRuckus C110 Version-
   CommscopeRuckus E510 Version-
   CommscopeRuckus H320 Version-
   CommscopeRuckus H350 Version-
   CommscopeRuckus H510 Version-
   CommscopeRuckus M510 Version-
   CommscopeRuckus R320 Version-
   CommscopeRuckus R510 Version-
   CommscopeRuckus R560 Version-
   CommscopeRuckus R610 Version-
   CommscopeRuckus R710 Version-
   CommscopeRuckus R720 Version-
   CommscopeRuckus R730 Version-
   CommscopeRuckus R750 Version-
   CommscopeRuckus Smartzone 100 Version-
   CommscopeRuckus Smartzone 100-d Version-
   CommscopeRuckus Smartzone 144 Version-
   CommscopeRuckus Smartzone 144-federal Version-
   CommscopeRuckus Smartzone 300 Version-
   CommscopeRuckus Smartzone 300-federal Version-
   CommscopeRuckus T310c Version-
   CommscopeRuckus T310d Version-
   CommscopeRuckus T310n Version-
   CommscopeRuckus T310s Version-
   CommscopeRuckus T350se Version-
   CommscopeRuckus T750 Version-
   CommscopeRuckus T750se Version-
CommscopeRuckus Smartzone Firmware Version6.1.2 Updatep2
   CommscopeRuckus Virtual Smartzone Version-
   CommscopeRuckus Virtual Smartzone-federal Version-
   CommscopeRuckus C110 Version-
   CommscopeRuckus E510 Version-
   CommscopeRuckus H320 Version-
   CommscopeRuckus H350 Version-
   CommscopeRuckus H510 Version-
   CommscopeRuckus M510 Version-
   CommscopeRuckus R320 Version-
   CommscopeRuckus R510 Version-
   CommscopeRuckus R560 Version-
   CommscopeRuckus R610 Version-
   CommscopeRuckus R710 Version-
   CommscopeRuckus R720 Version-
   CommscopeRuckus R730 Version-
   CommscopeRuckus R750 Version-
   CommscopeRuckus Smartzone 100 Version-
   CommscopeRuckus Smartzone 100-d Version-
   CommscopeRuckus Smartzone 144 Version-
   CommscopeRuckus Smartzone 144-federal Version-
   CommscopeRuckus Smartzone 300 Version-
   CommscopeRuckus Smartzone 300-federal Version-
   CommscopeRuckus T310c Version-
   CommscopeRuckus T310d Version-
   CommscopeRuckus T310n Version-
   CommscopeRuckus T310s Version-
   CommscopeRuckus T350se Version-
   CommscopeRuckus T750 Version-
   CommscopeRuckus T750se Version-
CommscopeRuckus Smartzone Firmware Version6.1.2 Updatep3
   CommscopeRuckus Virtual Smartzone Version-
   CommscopeRuckus Virtual Smartzone-federal Version-
   CommscopeRuckus C110 Version-
   CommscopeRuckus E510 Version-
   CommscopeRuckus H320 Version-
   CommscopeRuckus H350 Version-
   CommscopeRuckus H510 Version-
   CommscopeRuckus M510 Version-
   CommscopeRuckus R320 Version-
   CommscopeRuckus R510 Version-
   CommscopeRuckus R560 Version-
   CommscopeRuckus R610 Version-
   CommscopeRuckus R710 Version-
   CommscopeRuckus R720 Version-
   CommscopeRuckus R730 Version-
   CommscopeRuckus R750 Version-
   CommscopeRuckus Smartzone 100 Version-
   CommscopeRuckus Smartzone 100-d Version-
   CommscopeRuckus Smartzone 144 Version-
   CommscopeRuckus Smartzone 144-federal Version-
   CommscopeRuckus Smartzone 300 Version-
   CommscopeRuckus Smartzone 300-federal Version-
   CommscopeRuckus T310c Version-
   CommscopeRuckus T310d Version-
   CommscopeRuckus T310n Version-
   CommscopeRuckus T310s Version-
   CommscopeRuckus T350se Version-
   CommscopeRuckus T750 Version-
   CommscopeRuckus T750se Version-
CommscopeRuckus Smartzone Firmware Version7.0.0
   CommscopeRuckus Virtual Smartzone Version-
   CommscopeRuckus Virtual Smartzone-federal Version-
   CommscopeRuckus C110 Version-
   CommscopeRuckus E510 Version-
   CommscopeRuckus H320 Version-
   CommscopeRuckus H350 Version-
   CommscopeRuckus H510 Version-
   CommscopeRuckus M510 Version-
   CommscopeRuckus R320 Version-
   CommscopeRuckus R510 Version-
   CommscopeRuckus R560 Version-
   CommscopeRuckus R610 Version-
   CommscopeRuckus R710 Version-
   CommscopeRuckus R720 Version-
   CommscopeRuckus R730 Version-
   CommscopeRuckus R750 Version-
   CommscopeRuckus Smartzone 100 Version-
   CommscopeRuckus Smartzone 100-d Version-
   CommscopeRuckus Smartzone 144 Version-
   CommscopeRuckus Smartzone 144-federal Version-
   CommscopeRuckus Smartzone 300 Version-
   CommscopeRuckus Smartzone 300-federal Version-
   CommscopeRuckus T310c Version-
   CommscopeRuckus T310d Version-
   CommscopeRuckus T310n Version-
   CommscopeRuckus T310s Version-
   CommscopeRuckus T350se Version-
   CommscopeRuckus T750 Version-
   CommscopeRuckus T750se Version-
CommscopeRuckus Smartzone Firmware Version7.1.0
   CommscopeRuckus Virtual Smartzone Version-
   CommscopeRuckus Virtual Smartzone-federal Version-
   CommscopeRuckus C110 Version-
   CommscopeRuckus E510 Version-
   CommscopeRuckus H320 Version-
   CommscopeRuckus H350 Version-
   CommscopeRuckus H510 Version-
   CommscopeRuckus M510 Version-
   CommscopeRuckus R320 Version-
   CommscopeRuckus R510 Version-
   CommscopeRuckus R560 Version-
   CommscopeRuckus R610 Version-
   CommscopeRuckus R710 Version-
   CommscopeRuckus R720 Version-
   CommscopeRuckus R730 Version-
   CommscopeRuckus R750 Version-
   CommscopeRuckus Smartzone 100 Version-
   CommscopeRuckus Smartzone 100-d Version-
   CommscopeRuckus Smartzone 144 Version-
   CommscopeRuckus Smartzone 144-federal Version-
   CommscopeRuckus Smartzone 300 Version-
   CommscopeRuckus Smartzone 300-federal Version-
   CommscopeRuckus T310c Version-
   CommscopeRuckus T310d Version-
   CommscopeRuckus T310n Version-
   CommscopeRuckus T310s Version-
   CommscopeRuckus T350se Version-
   CommscopeRuckus T750 Version-
   CommscopeRuckus T750se Version-
CommscopeRuckus Network Director Version < 4.5.0.51
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.16% 0.374
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cve@mitre.org 8.5 1.8 6
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.