CRITICAL🇵🇱 Wersja polska

CVE-2025-46120

CVSS 9.8v3.1pub. 2025-07-21upd. 2025-08-05

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates outside permitted directories, allowing a remote unauthenticated attacker who can upload a template (e.g., via FTP) to escalate privileges and run arbitrary template code on the controller.

🤖 AI Analysis
How it works

The web server processes EJS (Embedded JavaScript) templates without proper path validation, allowing references to files outside permitted directories (path traversal, CWE-22). An attacker who is able to upload a malicious EJS template to the device — for example via FTP protocol — can cause the server to execute this template outside the allowed area of the file system. The result is privilege escalation and execution of arbitrary template code in the context of the controller.

Impact

A remote, unauthenticated attacker can gain full control over the wireless network controller, escalate privileges, and execute arbitrary code, which may result in compromise of confidentiality, integrity, and availability of the entire infrastructure.

Mitigation & patch

Update Ruckus Unleashed software to version at least 200.15.6.212.27 or 200.18.7.1.323, and ZoneDirector to version at least 10.5.1.0.282. It is also recommended to restrict access to the web interface and FTP service to trusted hosts and management networks only. Detailed information is available in the vendor security bulletin: https://support.ruckuswireless.com/security_bulletins/330

Who is affected

CommScope Ruckus Unleashed in versions prior to 200.15.6.212.27 and 200.18.7.1.323; CommScope Ruckus ZoneDirector in versions prior to 10.5.1.0.282. Listed hardware products: Ruckus M510-Jp, T350C, R350, E510, T811-Cm.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Commscope Ruckus C110

    HW
    Commscope
    all versions
  • Commscope Ruckus E510

    HW
    Commscope
    all versions
  • Commscope Ruckus H320

    HW
    Commscope
    all versions
  • Commscope Ruckus H350

    HW
    Commscope
    all versions
  • Commscope Ruckus H510

    HW
    Commscope
    all versions
  • Commscope Ruckus H550

    HW
    Commscope
    all versions
  • Commscope Ruckus M510

    HW
    Commscope
    all versions
  • Commscope Ruckus M510 Jp

    HW
    Commscope
    all versions
  • Commscope Ruckus R310

    HW
    Commscope
    all versions
  • Commscope Ruckus R320

    HW
    Commscope
    all versions
  • Commscope Ruckus R350

    HW
    Commscope
    all versions
  • Commscope Ruckus R350e

    HW
    Commscope
    all versions
  • Commscope Ruckus R510

    HW
    Commscope
    all versions
  • Commscope Ruckus R550

    HW
    Commscope
    all versions
  • Commscope Ruckus R560

    HW
    Commscope
    all versions
  • Commscope Ruckus R610

    HW
    Commscope
    all versions
  • Commscope Ruckus R650

    HW
    Commscope
    all versions
  • Commscope Ruckus R670

    HW
    Commscope
    all versions
  • Commscope Ruckus R710

    HW
    Commscope
    all versions
  • Commscope Ruckus R720

    HW
    Commscope
    all versions
  • Commscope Ruckus R730

    HW
    Commscope
    all versions
  • Commscope Ruckus R750

    HW
    Commscope
    all versions
  • Commscope Ruckus R760

    HW
    Commscope
    all versions
  • Commscope Ruckus R770

    HW
    Commscope
    all versions
  • Commscope Ruckus R850

    HW
    Commscope
    all versions
  • Commscope Ruckus T310c

    HW
    Commscope
    all versions
  • Commscope Ruckus T310n

    HW
    Commscope
    all versions
  • Commscope Ruckus T310s

    HW
    Commscope
    all versions
  • Commscope Ruckus T350c

    HW
    Commscope
    all versions
  • Commscope Ruckus T350d

    HW
    Commscope
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassLPEPath Traversal
CWE
References

Related vulnerabilities

CVE-2025-44954CRITICAL9.0PL ✓same product

Hardcoded SSH private key w RUCKUS SmartZone — dostęp root zdalnie

CVE-2025-44961CRITICAL9.9PL ✓same product

Command injection w RUCKUS SmartZone przez pole adresu IP

CVE-2025-46121CRITICAL9.8PL ✓same product

Format string RCE w CommScope Ruckus Unleashed — nieuwierzytelniony dostęp

CVE-2025-46117CRITICAL9.1PL ✓same product

Command injection w CommScope Ruckus — wykonanie komend jako root przez CLI

CVE-2025-46122CRITICAL9.1PL ✓same product

Command injection w Ruckus Unleashed — zdalne wykonanie poleceń jako root