CVE-2025-44958
RND因使用固定弱密钥存储密码导致安全风险,建议限制访问并使用安全协议以降低威胁。 2025-7-8 09:41:0 Author: claroty.com(查看原文) 阅读量:3 收藏

Medium Threat

CWE-257: Storing Passwords in a Recoverable Format

RND encrypts passwords with a hardcoded weak secret key and returns the passwords in plaintext. If the server were compromised, an attacker could gain all the plaintext passwords and decrypt them.

No patches have been supplied by the vendor at this time. To mitigate risk, network administrators should limit access to the wireless management environments that use these affected products, allowing a limited set of trusted users and their authenticated clients to manage Ruckus infrastructure via a secure protocol such as HTTPS or SSH.


文章来源: https://claroty.com/team82/disclosure-dashboard/cve-2025-44958
如有侵权请联系:admin#unsafe.sh