9.9

CVE-2025-44961

In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CommscopeRuckus Smartzone Firmware Version < 6.1.2
   CommscopeRuckus Virtual Smartzone Version-
   CommscopeRuckus Virtual Smartzone-federal Version-
   CommscopeRuckus C110 Version-
   CommscopeRuckus E510 Version-
   CommscopeRuckus H320 Version-
   CommscopeRuckus H350 Version-
   CommscopeRuckus H510 Version-
   CommscopeRuckus M510 Version-
   CommscopeRuckus R320 Version-
   CommscopeRuckus R510 Version-
   CommscopeRuckus R560 Version-
   CommscopeRuckus R610 Version-
   CommscopeRuckus R710 Version-
   CommscopeRuckus R720 Version-
   CommscopeRuckus R730 Version-
   CommscopeRuckus R750 Version-
   CommscopeRuckus Smartzone 100 Version-
   CommscopeRuckus Smartzone 100-d Version-
   CommscopeRuckus Smartzone 144 Version-
   CommscopeRuckus Smartzone 144-federal Version-
   CommscopeRuckus Smartzone 300 Version-
   CommscopeRuckus Smartzone 300-federal Version-
   CommscopeRuckus T310c Version-
   CommscopeRuckus T310d Version-
   CommscopeRuckus T310n Version-
   CommscopeRuckus T310s Version-
   CommscopeRuckus T350se Version-
   CommscopeRuckus T750 Version-
   CommscopeRuckus T750se Version-
CommscopeRuckus Smartzone Firmware Version6.1.2 Update-
   CommscopeRuckus Virtual Smartzone Version-
   CommscopeRuckus Virtual Smartzone-federal Version-
   CommscopeRuckus C110 Version-
   CommscopeRuckus E510 Version-
   CommscopeRuckus H320 Version-
   CommscopeRuckus H350 Version-
   CommscopeRuckus H510 Version-
   CommscopeRuckus M510 Version-
   CommscopeRuckus R320 Version-
   CommscopeRuckus R510 Version-
   CommscopeRuckus R560 Version-
   CommscopeRuckus R610 Version-
   CommscopeRuckus R710 Version-
   CommscopeRuckus R720 Version-
   CommscopeRuckus R730 Version-
   CommscopeRuckus R750 Version-
   CommscopeRuckus Smartzone 100 Version-
   CommscopeRuckus Smartzone 100-d Version-
   CommscopeRuckus Smartzone 144 Version-
   CommscopeRuckus Smartzone 144-federal Version-
   CommscopeRuckus Smartzone 300 Version-
   CommscopeRuckus Smartzone 300-federal Version-
   CommscopeRuckus T310c Version-
   CommscopeRuckus T310d Version-
   CommscopeRuckus T310n Version-
   CommscopeRuckus T310s Version-
   CommscopeRuckus T350se Version-
   CommscopeRuckus T750 Version-
   CommscopeRuckus T750se Version-
CommscopeRuckus Smartzone Firmware Version6.1.2 Updatep2
   CommscopeRuckus Virtual Smartzone Version-
   CommscopeRuckus Virtual Smartzone-federal Version-
   CommscopeRuckus C110 Version-
   CommscopeRuckus E510 Version-
   CommscopeRuckus H320 Version-
   CommscopeRuckus H350 Version-
   CommscopeRuckus H510 Version-
   CommscopeRuckus M510 Version-
   CommscopeRuckus R320 Version-
   CommscopeRuckus R510 Version-
   CommscopeRuckus R560 Version-
   CommscopeRuckus R610 Version-
   CommscopeRuckus R710 Version-
   CommscopeRuckus R720 Version-
   CommscopeRuckus R730 Version-
   CommscopeRuckus R750 Version-
   CommscopeRuckus Smartzone 100 Version-
   CommscopeRuckus Smartzone 100-d Version-
   CommscopeRuckus Smartzone 144 Version-
   CommscopeRuckus Smartzone 144-federal Version-
   CommscopeRuckus Smartzone 300 Version-
   CommscopeRuckus Smartzone 300-federal Version-
   CommscopeRuckus T310c Version-
   CommscopeRuckus T310d Version-
   CommscopeRuckus T310n Version-
   CommscopeRuckus T310s Version-
   CommscopeRuckus T350se Version-
   CommscopeRuckus T750 Version-
   CommscopeRuckus T750se Version-
CommscopeRuckus Smartzone Firmware Version6.1.2 Updatep3
   CommscopeRuckus Virtual Smartzone Version-
   CommscopeRuckus Virtual Smartzone-federal Version-
   CommscopeRuckus C110 Version-
   CommscopeRuckus E510 Version-
   CommscopeRuckus H320 Version-
   CommscopeRuckus H350 Version-
   CommscopeRuckus H510 Version-
   CommscopeRuckus M510 Version-
   CommscopeRuckus R320 Version-
   CommscopeRuckus R510 Version-
   CommscopeRuckus R560 Version-
   CommscopeRuckus R610 Version-
   CommscopeRuckus R710 Version-
   CommscopeRuckus R720 Version-
   CommscopeRuckus R730 Version-
   CommscopeRuckus R750 Version-
   CommscopeRuckus Smartzone 100 Version-
   CommscopeRuckus Smartzone 100-d Version-
   CommscopeRuckus Smartzone 144 Version-
   CommscopeRuckus Smartzone 144-federal Version-
   CommscopeRuckus Smartzone 300 Version-
   CommscopeRuckus Smartzone 300-federal Version-
   CommscopeRuckus T310c Version-
   CommscopeRuckus T310d Version-
   CommscopeRuckus T310n Version-
   CommscopeRuckus T310s Version-
   CommscopeRuckus T350se Version-
   CommscopeRuckus T750 Version-
   CommscopeRuckus T750se Version-
CommscopeRuckus Smartzone Firmware Version7.0.0
   CommscopeRuckus Virtual Smartzone Version-
   CommscopeRuckus Virtual Smartzone-federal Version-
   CommscopeRuckus C110 Version-
   CommscopeRuckus E510 Version-
   CommscopeRuckus H320 Version-
   CommscopeRuckus H350 Version-
   CommscopeRuckus H510 Version-
   CommscopeRuckus M510 Version-
   CommscopeRuckus R320 Version-
   CommscopeRuckus R510 Version-
   CommscopeRuckus R560 Version-
   CommscopeRuckus R610 Version-
   CommscopeRuckus R710 Version-
   CommscopeRuckus R720 Version-
   CommscopeRuckus R730 Version-
   CommscopeRuckus R750 Version-
   CommscopeRuckus Smartzone 100 Version-
   CommscopeRuckus Smartzone 100-d Version-
   CommscopeRuckus Smartzone 144 Version-
   CommscopeRuckus Smartzone 144-federal Version-
   CommscopeRuckus Smartzone 300 Version-
   CommscopeRuckus Smartzone 300-federal Version-
   CommscopeRuckus T310c Version-
   CommscopeRuckus T310d Version-
   CommscopeRuckus T310n Version-
   CommscopeRuckus T310s Version-
   CommscopeRuckus T350se Version-
   CommscopeRuckus T750 Version-
   CommscopeRuckus T750se Version-
CommscopeRuckus Smartzone Firmware Version7.1.0
   CommscopeRuckus Virtual Smartzone Version-
   CommscopeRuckus Virtual Smartzone-federal Version-
   CommscopeRuckus C110 Version-
   CommscopeRuckus E510 Version-
   CommscopeRuckus H320 Version-
   CommscopeRuckus H350 Version-
   CommscopeRuckus H510 Version-
   CommscopeRuckus M510 Version-
   CommscopeRuckus R320 Version-
   CommscopeRuckus R510 Version-
   CommscopeRuckus R560 Version-
   CommscopeRuckus R610 Version-
   CommscopeRuckus R710 Version-
   CommscopeRuckus R720 Version-
   CommscopeRuckus R730 Version-
   CommscopeRuckus R750 Version-
   CommscopeRuckus Smartzone 100 Version-
   CommscopeRuckus Smartzone 100-d Version-
   CommscopeRuckus Smartzone 144 Version-
   CommscopeRuckus Smartzone 144-federal Version-
   CommscopeRuckus Smartzone 300 Version-
   CommscopeRuckus Smartzone 300-federal Version-
   CommscopeRuckus T310c Version-
   CommscopeRuckus T310d Version-
   CommscopeRuckus T310n Version-
   CommscopeRuckus T310s Version-
   CommscopeRuckus T350se Version-
   CommscopeRuckus T750 Version-
   CommscopeRuckus T750se Version-
CommscopeRuckus Network Director Version < 4.5.0.51
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.342
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cve@mitre.org 9.9 3.1 6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.