Ruckus vRIoT IoT Controller < 3.0.0.0 Hardcoded Tokens RCE
Vulnerability Description
The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2004 running with root privileges. Authentication to this service relies on a hardcoded Time-based One-Time Password (TOTP) secret and an embedded static token. An attacker who extracts these credentials from the appliance or a compromised device can generate valid authentication tokens and execute arbitrary OS commands with root privileges, resulting in complete system compromise.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-69425
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Ivan Racic
References
More from RUCKUS Networks
View All →Affected Vendor
RUCKUS Networks
View all reports →