关键漏洞信息 漏洞标识 Advisory ID: MCSAID-2025-012 CVE ID: CVE-2025-67305 漏洞概述 产品: RUCKUS Network Director 漏洞类型: 使用硬编码凭据 (CWE-798) 发现者: Ivan Racic of Marlink Cyber 报告日期: 2025-09-24 发布日期: 2025-10-31 严重性: 高(8.8) 漏洞描述 The RUCKUS Network Director OVA appliance contains hardcoded SSH keys for the user, allowing an attacker to authenticate via SSH without a password and gain access to the PostgreSQL database and web interface. 影响版本 验证漏洞 The hardcoded SSH keys are located at on the appliance. 潜在影响 Full access to PostgreSQL database with superuser privileges. Create administrative users for the web interface. Read/write access to application data. Remote operating system access. Potential for further privilege escalation. 缓解措施 Update RUCKUS Network Director to version 4.5.0.56 or later. Restrict SSH access. Audit existing deployments. 参考资料 Vendor Advisory: RUCKUS Network Director: Critical Security Bypass Vulnerability Leading to Remote Code Execution and Shell Access