Security Bulletins

Security Bulletin 20250710

Title: Reported vulnerabilities in RUCKUS SmartZone and RUCKUS Network Director: CVE-2025-44957, CVE-2025-44962 ... Description:

Reported vulnerabilities in RUCKUS SmartZone and RUCKUS Network Director: CVE-2025-44957, CVE-2025-44962, CVE-2025-44954, CVE-2025-44960, CVE-2025-44961, CVE-2025-44963, CVE-2025-44955, CVE-2025-6243, CVE-2025-44958

It has been reported by CC/CERT that RUCKUS SmartZone Controller (SZ) and RUCKUS Network Director (RND) contain a number of critical vulnerabilities. If exploited, these vulnerabilities may allow a remote, unauthenticated attacker to gain shell access to the affected device. 

RUCKUS is actively investigating in order to validate the reported vulnerabilities and will provide updates as new information becomes available.

RUCKUS would like to recognize and thank Noam Moshe of Claroty Team82 for finding these issues.

Release Date:
July 10, 2025
Edit Date:
July 10, 2025
Version:
1.0

Applicable To The Following Products

RUCKUS Network Director (RND)

The Ruckus Network Director (RND) is application software, which targets an "on-premise" deployment model and establishes a level above Ruckus SmartZone (SZ) controllers, in order to manage the entire Ruckus Network in large scale multi-cluster infrastructures. The Network Director incorporates network inventory and access point registration components into a single application User Dashboard Interface.  Network Director helps to improve network operations efficiency through an extensive feature set including:

- a single pane screen with network health monitoring across multiple SZ clusters, which provides network wide and node specific visibility.

- detailed network inventory, including network nodes and licenses, which helps to plan necessary network extensions and upgrades.

- access points' movement by one or in bulk between SmartZone controllers.

- customer driven access point registration rules and ability to park AP on a particular SZ cluster automatically, which solves problems of bulk AP roll-outs by non-experienced technicians.

- cluster backup scheduling managment.

Network Director brings Ruckus customers a useful set of tools for improvment of their day-to-day operations of the Ruckus Network.


SmartZone 100 (SZ-100)

SmartZone™ 100 (SZ-100) is the most scalable, resilient, and highest performing Wireless LAN controller within the Ruckus family of WLAN controllers for enterprises around the world. It manages up to 1,024 ZoneFlex Smart Wi-Fi access points, 2,000 WLANs, and 25,000 clients per device. Its unique SmartZone architecture allows the SZ-100 to be deployed in a 3+1 Active-Active cluster. With Active-Active clustering all members (up to 4) of a cluster will actively manage APs in the network, providing enhanced resiliency for high availability requirements. With clustering, the SZ-100 can manage up to 3,000 APs and 60,000 clients.

Smart licensing allows customers to manage all licensing needs online at https://support.ruckuswireless.com. With Smart licensing, customers have the ability to buy and assign licenses at a granular level down to 1 (one) AP license.

SmartZone 100-D (SZ100-D)

The SmartZone™ Data Plane appliance (SZ100-D) is a wireless LAN data plane appliance, that comes in physical form factor as a family of two products, first with 1Gbps and second with 10Gbps throughput support. Made to work seamlessly with Ruckus SmartZone network controllers, the SmartZone Data Plane appliance enables secure tunneled WLANs from Ruckus APs while minimizing CAPEX spending and maximizing Wi-Fi deployment flexibility and scale.

SZ100-D appliance benefits businesses that have leaner IT departments with limited virtualization expertise or that wish to further simplify deployments. Operators, ISPs and large enterprises can deploy the SZ100-D in a centralized data center with SmartZone network controllers, or at specific venues in a distributed topology. In addition, organizations have the flexibility to deploy SZ100-D at each of the tenant locations based on their requirements.

The Data Plane appliance brings multiple high value features, such as:

  - High performance DHCP-server

  - NAT (Network Address Translation)

  - L3 Roaming

  - Flexi-VPN


SmartZone 144 (SZ-144)

SmartZone™ 144 (SZ-144) is the next-generation high performing Wireless LAN controller within the RUCKUS family of WLAN controllers for enterprises around the world. It manages up to 2000 RUCKUS Wi-Fi access points or 400 switches, and 40,000 clients per controller. Its unique SmartZone architecture allows the SZ-144 to be deployed in a 3+1 Active-Active cluster. With Active-Active clustering all members (up to 4) of a cluster will actively manage APs and switches in the network, providing enhanced resiliency for high availability requirements. With clustering, the SZ-144 can manage up to 6,000APs, 1200 switches and 120,000 clients.

Smart licensing allows customers to manage all licensing needs online at https://support.ruckuswireless.com. With Smart licensing, customers have the ability to buy and assign licenses at a granular level down to 1 (one) AP license.

SmartZone 144 (SZ-144) - Federal

SmartZone™ 144 (SZ-144) is the next-generation high performing Wireless LAN controller within the Ruckus family of WLAN controllers for enterprises around the world. It manages up to 2000 Commscope Wi-Fi access points, 400 switches,and 40,000 clients per controller. Its unique SmartZone architecture allows the SZ-144 to be deployed in a 3+1 Active-Active cluster. With Active-Active clustering all members (up to 4) of a cluster will actively manage APs and switches in the network, providing enhanced resiliency for high availability requirements. With clustering, the SZ-144 can manage up to 6,000APs, 1200 switches and 120,000 clients.

Smart licensing allows customers to manage all licensing needs online at https://support.ruckuswireless.com. With Smart licensing, customers have the ability to buy and assign licenses ata granular level down to 1 (one) AP license.

SmartZone 144-Dataplane (SZ144-D)

The SmartZone™ 144 Data Plane appliance (SZ144-D) is a wireless LAN data plane appliance, that comes in physical form factor with four (4) 1Gbps and four (4) 10Gbps ports. Made to work seamlessly with Ruckus SmartZone network controllers (vSZ-E, vSZ-H), the SmartZone Data Plane appliance (SZ144-D) enables secure tunneled WLANs from Ruckus APs while minimizing CAPEX spending and maximizing Wi-Fi deployment flexibility and scale.

SZ144-D appliance benefits businesses that have leaner IT departments with limited virtualization expertise or that wish to further simplify deployments. Operators, ISPs and large enterprises can deploy the SZ144-D in a centralized data center with SmartZone network controllers, or at specific venues in a distributed topology. In addition, organizations have the flexibility to deploy SZ144-D at each of the tenant locations based on their requirements.

The Data Plane appliance brings multiple high value features, such as:

  - High performance DHCP-server

  - NAT (Network Address Translation)

  - L3 Roaming

  - Flexi-VPN

SmartZone 300 (SZ300)

The SmartZone 300 (SZ300) Flagship Large Scale WLAN Controller is designed for Service Provider and Large Enterprises, which prefer to use appliances. The Carrier Grade platform supports N+1 Active/Active clustering, comprehensive integrated management functionality, high performance operations and flexibility to address many different implementation scenarios.

The SZ300 supports up to 10,000 AP and 100,000 Clients per unit and 30,000 AP and 300,000 Clients per 3+1 Active/Active Cluster, and runs SmartZone 3.5+ release firmware.


SmartZone 300 (SZ300) - Federal

The SmartZone 300 (SZ300) Flagship Large Scale WLAN Controller is designed for Service Provider and Large Enterprises, which prefer to use appliances. The Carrier Grade platform supports N+1 Active/Active clustering, comprehensive integrated management functionality, high performance operations and flexibility to address many different implementation scenarios.

The SZ300 supports up to 10,000 AP and 100,000 Clients per unit and 30,000 AP and 300,000 Clients per 3+1 Active/Active Cluster, and runs SmartZone 3.5+ release firmware.


Virtual SmartZone - (vSZ)

Note: The Virtual SmartCell Gateway (vSCG) has a new name: Virtual SmartZone (vSZ). Same product, new name.

The Ruckus Virtual SmartZone (vSZ) is an NFV-based and cloud-ready WLAN controller for service providers and enterprises ready to elevate their WLAN deployment to the next level of flexibility, resiliency, andscale. vSZ operates in two modes: Essentials and High-Capacity.

Enterprises will find that the Essentials mode (vSZ-E) delivers world-beating Wi-Fi performance in an incredibly easy to manage and cost-effective package that’s friendly to both virtualized and/or distributed environments.

Managed Service Providers deploying the High-Capacity mode (vSZ-H) in their data center will experience a scalable carrier-class Wi-Fi rollout brimming with unique service provider features ready to back up their service level agreements. 


Virtual SmartZone - (vSZ) - Federal

Note: The Virtual SmartCell Gateway (vSCG) has a new name: Virtual SmartZone (vSZ). Same product, new name.

The Ruckus Virtual SmartZone (vSZ) is an NFV-based and cloud-ready WLAN controller for service providers and enterprises ready to elevate their WLAN deployment to the next level of flexibility, resiliency, andscale. vSZ operates in two modes: Essentials and High-Capacity.

Enterprises will find that the Essentials mode (vSZ-E) delivers world-beating Wi-Fi performance in an incredibly easy to manage and cost-effective package that’s friendly to both virtualized and/or distributed environments.

Managed Service Providers deploying the High-Capacity mode (vSZ-H) in their data center will experience a scalable carrier-class Wi-Fi rollout brimming with unique service provider features ready to back up their service level agreements. 


Virtual SmartZone-Dataplane (vSZ-D)

The Ruckus Virtual SmartZone-Dataplane (vSZ-D) is available on the vSZ platform and offers organizations more flexibility in deploying the SZ dataplane as needed in an NFV architechture-aligned fashion.   Deploying vSZ-D offers secured tunneling of user data traffic that encrypts payload traffic, maintains flat network topology, enables mobility across L2 subnets, supports POS data traffic for PCI compliance, and offers differentiated per site policy control and QoS, etc.


Virtual SmartZone-Dataplane (vSZ-D) - Federal

The Ruckus Virtual SmartZone-Dataplane (vSZ-D) is available on the vSZ platform and offers organizations more flexibility in deploying the SZ dataplane as needed in an NFV architechture-aligned fashion.   Deploying vSZ-D offers secured tunneling of user data traffic that encrypts payload traffic, maintains flat network topology, enables mobility across L2 subnets, supports POS data traffic for PCI compliance, and offers differentiated per site policy control and QoS, etc.


Working...Please wait

This is here to prevent you from accidentally submitting twice.

The page will automatically refresh.

Alert!!

Close