CVE-2025-46122 Details
Description
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled input to the shell without adequate validation, enabling a remote attacker to specify a target by MAC address and execute arbitrary commands as root.
A command injection vulnerability has been identified in CommScope Ruckus Unleashed and ZoneDirector management platforms. This vulnerability exists in versions prior to Unleashed 200.15.6.212.14 and 200.17.7.0.139, as well as ZoneDirector 10.5.1.0.282. The issue arises in the authenticated diagnostics API endpoint '/admin/_cmdstat.jsp', where attacker-controlled input is inadequately validated before being passed to the shell. This flaw enables remote attackers to execute arbitrary commands as root by specifying the MAC address of a targeted device.
Users are advised to update to Ruckus Unleashed versions 200.18.7.1.323 or later, and ZoneDirector versions 10.5.1.0.282 or later. After updating, all passwords should be changed, existing management interface certificates revoked, and private keys regenerated.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sector7.computest.nl/post/2025-07-ruckus-unleashed/ | [email protected] | ExploitThird Party Advisory |
| https://support.ruckuswireless.com/security_bulletins/330 | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| ruckuswireless ruckus unleashed | < 200.15.6.212.14 >= 200.17, < 200.17.7.0.139 |
CPE
Remediation
| |
| ruckuswireless ruckus zonedirector | < 10.5.1.0.279 |
CPE
Remediation
| |
| commscope ruckus c110 | All versions |
CPE
Remediation
| |
| commscope ruckus e510 | All versions |
CPE
Remediation
| |
| commscope ruckus h320 | All versions |
CPE
Remediation
| |
| commscope ruckus h350 | All versions |
CPE
Remediation
| |
| commscope ruckus h510 | All versions |
CPE
Remediation
| |
| commscope ruckus h550 | All versions |
CPE
Remediation
| |
| commscope ruckus m510 | All versions |
CPE
Remediation
| |
| commscope ruckus m510-jp | All versions |
CPE
Remediation
| |
| commscope ruckus r310 | All versions |
CPE
Remediation
| |
| commscope ruckus r320 | All versions |
CPE
Remediation
| |
| commscope ruckus r350 | All versions |
CPE
Remediation
| |
| commscope ruckus r350e | All versions |
CPE
Remediation
| |
| commscope ruckus r510 | All versions |
CPE
Remediation
| |
| commscope ruckus r550 | All versions |
CPE
Remediation
| |
| commscope ruckus r560 | All versions |
CPE
Remediation
| |
| commscope ruckus r610 | All versions |
CPE
Remediation
| |
| commscope ruckus r650 | All versions |
CPE
Remediation
| |
| commscope ruckus r670 | All versions |
CPE
Remediation
| |
| commscope ruckus r710 | All versions |
CPE
Remediation
| |
| commscope ruckus r720 | All versions |
CPE
Remediation
| |
| commscope ruckus r730 | All versions |
CPE
Remediation
| |
| commscope ruckus r750 | All versions |
CPE
Remediation
| |
| commscope ruckus r760 | All versions |
CPE
Remediation
| |
| commscope ruckus r770 | All versions |
CPE
Remediation
| |
| commscope ruckus r850 | All versions |
CPE
Remediation
| |
| commscope ruckus t310c | All versions |
CPE
Remediation
| |
| commscope ruckus t310n | All versions |
CPE
Remediation
| |
| commscope ruckus t310s | All versions |
CPE
Remediation
| |
| commscope ruckus t350c | All versions |
CPE
Remediation
| |
| commscope ruckus t350d | All versions |
CPE
Remediation
| |
| commscope ruckus t350se | All versions |
CPE
Remediation
| |
| commscope ruckus t610 | All versions |
CPE
Remediation
| |
| commscope ruckus t670 | All versions |
CPE
Remediation
| |
| commscope ruckus t710 | All versions |
CPE
Remediation
| |
| commscope ruckus t710s | All versions |
CPE
Remediation
| |
| commscope ruckus t750 | All versions |
CPE
Remediation
| |
| commscope ruckus t750se | All versions |
CPE
Remediation
| |
| commscope ruckus t811-cm | All versions |
CPE
Remediation
| |
| commscope ruckus t811-cm (non-sfp) | All versions |
CPE
Remediation
| |
| commscope zonedirector 1200 | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Aug 5, 2025 | Initial Analysis | [email protected] |
| Jul 23, 2025 | CVE Modified | CISA-ADP |
| Jul 22, 2025 | CVE Modified | [email protected] |
| Jul 22, 2025 | CVE Modified | CISA-ADP |
| Jul 21, 2025 | New CVE Received | [email protected] |