PT-2025-30284 · Commscope · Ruckus Unleashed

René Ammerlaan

·

Published

2025-07-21

·

Updated

2025-07-31

·

CVE-2025-46122

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CommScope Ruckus Unleashed versions prior to 200.15.6.212.14 CommScope Ruckus Unleashed versions prior to 200.17.7.0.139
Description The authenticated diagnostics API endpoint /admin/ cmdstat.jsp passes attacker-controlled input to the shell without adequate validation. This enables a remote attacker to specify a target by MAC address and execute arbitrary commands as root.
Recommendations CommScope Ruckus Unleashed versions prior to 200.15.6.212.14: Update to version 200.15.6.212.14 or later. CommScope Ruckus Unleashed versions prior to 200.17.7.0.139: Update to version 200.17.7.0.139 or later.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-46122

Affected Products

Ruckus Unleashed