CVE-2025-69426 Details
Description
The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user account within an initialization script. The SSH service is network-accessible without IP-based restrictions. Although the configuration disables SCP and pseudo-TTY allocation, an attacker can authenticate using the hardcoded credentials and establish SSH local port forwarding to access the Docker socket. By mounting the host filesystem via Docker, an attacker can escape the container and execute arbitrary OS commands as root on the underlying vRIoT controller, resulting in complete system compromise.
A remote code execution vulnerability exists in Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA). The vulnerability arises from hardcoded SSH credentials for an operating system user account, embedded within an initialization script. The SSH service is accessible over the network without IP-based restrictions. While the configuration disables SCP and pseudo-TTY allocation, an attacker can use the hardcoded credentials to authenticate and establish SSH local port forwarding to access the Docker socket. This access allows the attacker to mount the host filesystem via Docker, escape the container, and execute arbitrary operating system commands as root on the underlying vRIoT controller, resulting in complete system compromise.
Users are advised to upgrade to Ruckus IoT Controller version 3.0.0.0 (GA) or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 9, 2026CISA-ADP
Assessed Jan 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-732 | Incorrect Permission Assignment for Critical Resource | [email protected] |
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Ruckus vRIoT IoT Controller | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 9, 2026 | New CVE Received | [email protected] |
Volerion