CVE-2025-6243
RND平台存在内置用户sshuser及其硬编码密钥漏洞,允许未经授权访问。目前无补丁,建议限制访问并使用安全协议管理。 2025-7-8 09:40:0 Author: claroty.com(查看原文) 阅读量:2 收藏

Critical Threat

CWE-321: Use of Hard-coded Cryptographic Key

A built-in user called sshuser, with root privileges, exists on the RND platform. Both public and private ssh keys exist in the sshuser home directory. Anyone with the private key can access an RND server as sshuser.

No patches have been supplied by the vendor at this time. To mitigate risk, network administrators should limit access to the wireless management environments that use these affected products, allowing a limited set of trusted users and their authenticated clients to manage Ruckus infrastructure via a secure protocol such as HTTPS or SSH.


文章来源: https://claroty.com/team82/disclosure-dashboard/cve-2025-6243
如有侵权请联系:admin#unsafe.sh