logo

Double Critical: Hardcoded Secrets Expose Ruckus IoT Controllers to Root RCE

ID: 93da4a16-1577-554c-9386-43d5ed6bb488

STIX ID: report--93da4a16-1577-554c-9386-43d5ed6bb488

Feed Name: securityonline.info

Threat Score
95/100

Date Published: 2026-01-13

Date Updated: 2026-04-23

Author: Ddos

...
...

A pair of critical vulnerabilities in the Ruckus vRIoT IoT Controller (CVE-2025-69425 and CVE-2025-69426) allow remote attackers to achieve root on affected devices: one is a hardcoded TOTP/backdoor accessible via TCP port 2004 that permits arbitrary root command execution, and the other leverages hardcoded SSH credentials to tunnel to the Docker socket and escape to the host. Ruckus fixed both issues in firmware 3.0.0.0 (GA); administrators are urged to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.