CRITICAL🇵🇱 Wersja polska

CVE-2025-46117

CVSS 9.1v3.1pub. 2025-07-21upd. 2025-08-05

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where a hidden debug script `.ap_debug.sh` invoked from the restricted CLI does not properly sanitize its input, allowing an authenticated attacker to execute arbitrary commands as root on the controller or specified target.

🤖 AI Analysis
How it works

The command injection vulnerability (CWE-78) consists of the hidden debugging script `.ap_debug.sh`, available from the restricted CLI level, not applying proper sanitization of input data. An attacker with access to an administrative account can inject arbitrary system commands as arguments to this script. The executed commands are run in the root account context — both on the controller itself and on the remotely specified target device. The network vector (AV:N) means that the attack can be conducted remotely over the network.

Impact

The attacker gains full control over the controller or target network device with root privileges, enabling data theft, configuration modification, malicious software installation, and further lateral movement within the network infrastructure.

Mitigation & patch

The software should be updated to Ruckus Unleashed version 200.15.6.212.14 or 200.17.7.0.139 or later, and Ruckus ZoneDirector to version 10.5.1.0.279 or later. Detailed instructions are available in the vendor's security bulletin: https://support.ruckuswireless.com/security_bulletins/330. As a temporary measure, CLI access should be restricted exclusively to trusted, authorized administrative networks.

Who is affected

CommScope Ruckus Unleashed in versions prior to 200.15.6.212.14 and 200.17.7.0.139, as well as Ruckus ZoneDirector in versions prior to 10.5.1.0.279. Vulnerable devices include: Ruckus M510-JP, T350C, R350, E510, T811-CM.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Commscope Ruckus C110

    HW
    Commscope
    all versions
  • Commscope Ruckus E510

    HW
    Commscope
    all versions
  • Commscope Ruckus H320

    HW
    Commscope
    all versions
  • Commscope Ruckus H350

    HW
    Commscope
    all versions
  • Commscope Ruckus H510

    HW
    Commscope
    all versions
  • Commscope Ruckus H550

    HW
    Commscope
    all versions
  • Commscope Ruckus M510

    HW
    Commscope
    all versions
  • Commscope Ruckus M510 Jp

    HW
    Commscope
    all versions
  • Commscope Ruckus R310

    HW
    Commscope
    all versions
  • Commscope Ruckus R320

    HW
    Commscope
    all versions
  • Commscope Ruckus R350

    HW
    Commscope
    all versions
  • Commscope Ruckus R350e

    HW
    Commscope
    all versions
  • Commscope Ruckus R510

    HW
    Commscope
    all versions
  • Commscope Ruckus R550

    HW
    Commscope
    all versions
  • Commscope Ruckus R560

    HW
    Commscope
    all versions
  • Commscope Ruckus R610

    HW
    Commscope
    all versions
  • Commscope Ruckus R650

    HW
    Commscope
    all versions
  • Commscope Ruckus R670

    HW
    Commscope
    all versions
  • Commscope Ruckus R710

    HW
    Commscope
    all versions
  • Commscope Ruckus R720

    HW
    Commscope
    all versions
  • Commscope Ruckus R730

    HW
    Commscope
    all versions
  • Commscope Ruckus R750

    HW
    Commscope
    all versions
  • Commscope Ruckus R760

    HW
    Commscope
    all versions
  • Commscope Ruckus R770

    HW
    Commscope
    all versions
  • Commscope Ruckus R850

    HW
    Commscope
    all versions
  • Commscope Ruckus T310c

    HW
    Commscope
    all versions
  • Commscope Ruckus T310n

    HW
    Commscope
    all versions
  • Commscope Ruckus T310s

    HW
    Commscope
    all versions
  • Commscope Ruckus T350c

    HW
    Commscope
    all versions
  • Commscope Ruckus T350d

    HW
    Commscope
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2025-44954CRITICAL9.0PL ✓same product

Hardcoded SSH private key w RUCKUS SmartZone — dostęp root zdalnie

CVE-2025-44961CRITICAL9.9PL ✓same product

Command injection w RUCKUS SmartZone przez pole adresu IP

CVE-2025-46121CRITICAL9.8PL ✓same product

Format string RCE w CommScope Ruckus Unleashed — nieuwierzytelniony dostęp

CVE-2025-46120CRITICAL9.8PL ✓same product

Path traversal w Ruckus Unleashed/ZoneDirector umożliwia RCE bez uwierzytelnienia

CVE-2025-46122CRITICAL9.1PL ✓same product

Command injection w Ruckus Unleashed — zdalne wykonanie poleceń jako root