CRITICAL🇵🇱 Wersja polska

CVE-2025-46121

CVSS 9.8v3.1pub. 2025-07-21upd. 2025-08-05

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to snprintf as the format string. A remote attacker can exploit this flaw either by sending a crafted request to the authenticated endpoint `/admin/_conf.jsp`, or without authentication and without direct network access to the controller by spoofing the MAC address of a favourite station and embedding malicious format specifiers in the DHCP hostname field, resulting in unauthenticated format-string processing and arbitrary code execution on the controller.

🤖 AI Analysis
How it works

The functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass the client's hostname directly to `snprintf` as a format string instead of as an argument. An attacker can exploit this vulnerability in two ways: by sending a crafted request to the authenticated endpoint `/admin/_conf.jsp`, or — without authentication and without direct access to the controller — by spoofing the MAC address of a station on the favorites list and placing malicious format specifiers in the DHCP hostname field. In the second scenario, the controller processes the malicious format string without any authentication, leading to arbitrary code execution.

Impact

An attacker can gain full control over the controller, which includes violation of confidentiality, integrity, and system availability — including potential takeover of the entire wireless infrastructure managed by the controller.

Mitigation & patch

Update Ruckus Unleashed software to version 200.15.6.212.14 or 200.17.7.0.139 (or newer). Detailed information is available in the vendor's security bulletin at https://support.ruckuswireless.com/security_bulletins/330. Until the patch is implemented, it is recommended to restrict access to the controller's administrative interface and monitor anomalies in DHCP traffic.

Who is affected

CommScope Ruckus Unleashed versions prior to 200.15.6.212.14 and 200.17.7.0.139, on devices: Ruckus M510-JP, Ruckus T350C, Ruckus R350, Ruckus E510, Ruckus T811-CM.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Commscope Ruckus C110

    HW
    Commscope
    all versions
  • Commscope Ruckus E510

    HW
    Commscope
    all versions
  • Commscope Ruckus H320

    HW
    Commscope
    all versions
  • Commscope Ruckus H350

    HW
    Commscope
    all versions
  • Commscope Ruckus H510

    HW
    Commscope
    all versions
  • Commscope Ruckus H550

    HW
    Commscope
    all versions
  • Commscope Ruckus M510

    HW
    Commscope
    all versions
  • Commscope Ruckus M510 Jp

    HW
    Commscope
    all versions
  • Commscope Ruckus R310

    HW
    Commscope
    all versions
  • Commscope Ruckus R320

    HW
    Commscope
    all versions
  • Commscope Ruckus R350

    HW
    Commscope
    all versions
  • Commscope Ruckus R350e

    HW
    Commscope
    all versions
  • Commscope Ruckus R510

    HW
    Commscope
    all versions
  • Commscope Ruckus R550

    HW
    Commscope
    all versions
  • Commscope Ruckus R560

    HW
    Commscope
    all versions
  • Commscope Ruckus R610

    HW
    Commscope
    all versions
  • Commscope Ruckus R650

    HW
    Commscope
    all versions
  • Commscope Ruckus R670

    HW
    Commscope
    all versions
  • Commscope Ruckus R710

    HW
    Commscope
    all versions
  • Commscope Ruckus R720

    HW
    Commscope
    all versions
  • Commscope Ruckus R730

    HW
    Commscope
    all versions
  • Commscope Ruckus R750

    HW
    Commscope
    all versions
  • Commscope Ruckus R760

    HW
    Commscope
    all versions
  • Commscope Ruckus R770

    HW
    Commscope
    all versions
  • Commscope Ruckus R850

    HW
    Commscope
    all versions
  • Commscope Ruckus T310c

    HW
    Commscope
    all versions
  • Commscope Ruckus T310n

    HW
    Commscope
    all versions
  • Commscope Ruckus T310s

    HW
    Commscope
    all versions
  • Commscope Ruckus T350c

    HW
    Commscope
    all versions
  • Commscope Ruckus T350d

    HW
    Commscope
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2025-44954CRITICAL9.0PL ✓same product

Hardcoded SSH private key w RUCKUS SmartZone — dostęp root zdalnie

CVE-2025-44961CRITICAL9.9PL ✓same product

Command injection w RUCKUS SmartZone przez pole adresu IP

CVE-2025-46120CRITICAL9.8PL ✓same product

Path traversal w Ruckus Unleashed/ZoneDirector umożliwia RCE bez uwierzytelnienia

CVE-2025-46117CRITICAL9.1PL ✓same product

Command injection w CommScope Ruckus — wykonanie komend jako root przez CLI

CVE-2025-46122CRITICAL9.1PL ✓same product

Command injection w Ruckus Unleashed — zdalne wykonanie poleceń jako root