Home
CRITICAL: 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HDefault status
unknown
Any version before 6.1.2p3 Refresh Build
affected
Description
In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
Any version before 6.1.2p3 Refresh Build
References
www.kb.cert.org/vuls/id/613753
webresources.commscope.com/...5f44ac3bd311f095821adcaa92e24e
claroty.com/team82/disclosure-dashboard/cve-2025-44961