CVE 10 CRITICAL

Ruckus vRIoT IoT Controller < 3.0.0.0 Hardcoded SSH Credentials RCE_CVE-2025-69426

10 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/

Description

The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user account within an initialization script. The SSH service is network-accessible without IP-based restrictions. Although the configuration disables SCP and pseudo-TTY allocation, an attacker can authenticate using the hardcoded credentials and establish SSH local port forwarding to access the Docker socket. By mounting the host filesystem via Docker, an attacker can escape the container and execute arbitrary OS commands as root on the underlying vRIoT controller, resulting in complete system compromise.

AI Analysis

Hardcoded SSH credentials in Ruckus vRIoT IoT Controller firmware allow for remote code execution and complete system compromise

Basic Information

ID CVE-2025-69426
Source VulnCheck
Published Jan 9, 2026 at 16:15

Affected Product

Vendor RUCKUS Networks
Product vRIoT IOT Controller
Version 2.3.0.0 (GA)
Affected Versions RUCKUS Networks vRIoT IOT Controller 2.3.0.0 (GA)
RUCKUS Networks vRIoT IOT Controller 2.3.1.0 (MR)
RUCKUS Networks vRIoT IOT Controller 2.4.0.0 (GA)

CWE Classification

AI Assessment

AI Score 10 / 10
AI Severity Critical
Vendor Ruckus Networks
Product vRIoT IOT Controller
Version 2.3.0.0 (GA), 2.3.1.0 (MR), 2.4.0.0 (GA)

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.