CRITICAL🇵🇱 Wersja polska

CVE-2025-46122

CVSS 9.1v3.1pub. 2025-07-21upd. 2025-08-05

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled input to the shell without adequate validation, enabling a remote attacker to specify a target by MAC address and execute arbitrary commands as root.

🤖 AI Analysis
How it works

The diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled data directly to the system shell without proper input validation (CWE-77: command injection). An attacker with access to an administrator account can specify a target via MAC address and inject arbitrary system commands. These commands are executed in the context of the root account, providing full control over the device.

Impact

An attacker can execute arbitrary commands with root privileges on the vulnerable device, leading to complete device compromise, loss of confidentiality, integrity and system availability, and potential lateral movement within the network.

Mitigation & patch

Update Ruckus Unleashed software to version 200.15.6.212.14 or later (for the 200.15 branch) or to version 200.17.7.0.139 or later (for the 200.17 branch). Detailed information is available in the vendor's security bulletin: https://support.ruckuswireless.com/security_bulletins/330. Until the patch is deployed, it is recommended to restrict access to the device administrative interface only to trusted hosts and management networks.

Who is affected

CommScope Ruckus Unleashed in versions prior to 200.15.6.212.14 and 200.17.7.0.139, installed on devices: Ruckus M510-JP, Ruckus T350C, Ruckus R350, Ruckus E510, Ruckus T811-CM.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Commscope Ruckus C110

    HW
    Commscope
    all versions
  • Commscope Ruckus E510

    HW
    Commscope
    all versions
  • Commscope Ruckus H320

    HW
    Commscope
    all versions
  • Commscope Ruckus H350

    HW
    Commscope
    all versions
  • Commscope Ruckus H510

    HW
    Commscope
    all versions
  • Commscope Ruckus H550

    HW
    Commscope
    all versions
  • Commscope Ruckus M510

    HW
    Commscope
    all versions
  • Commscope Ruckus M510 Jp

    HW
    Commscope
    all versions
  • Commscope Ruckus R310

    HW
    Commscope
    all versions
  • Commscope Ruckus R320

    HW
    Commscope
    all versions
  • Commscope Ruckus R350

    HW
    Commscope
    all versions
  • Commscope Ruckus R350e

    HW
    Commscope
    all versions
  • Commscope Ruckus R510

    HW
    Commscope
    all versions
  • Commscope Ruckus R550

    HW
    Commscope
    all versions
  • Commscope Ruckus R560

    HW
    Commscope
    all versions
  • Commscope Ruckus R610

    HW
    Commscope
    all versions
  • Commscope Ruckus R650

    HW
    Commscope
    all versions
  • Commscope Ruckus R670

    HW
    Commscope
    all versions
  • Commscope Ruckus R710

    HW
    Commscope
    all versions
  • Commscope Ruckus R720

    HW
    Commscope
    all versions
  • Commscope Ruckus R730

    HW
    Commscope
    all versions
  • Commscope Ruckus R750

    HW
    Commscope
    all versions
  • Commscope Ruckus R760

    HW
    Commscope
    all versions
  • Commscope Ruckus R770

    HW
    Commscope
    all versions
  • Commscope Ruckus R850

    HW
    Commscope
    all versions
  • Commscope Ruckus T310c

    HW
    Commscope
    all versions
  • Commscope Ruckus T310n

    HW
    Commscope
    all versions
  • Commscope Ruckus T310s

    HW
    Commscope
    all versions
  • Commscope Ruckus T350c

    HW
    Commscope
    all versions
  • Commscope Ruckus T350d

    HW
    Commscope
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-44954CRITICAL9.0PL ✓same product

Hardcoded SSH private key w RUCKUS SmartZone — dostęp root zdalnie

CVE-2025-44961CRITICAL9.9PL ✓same product

Command injection w RUCKUS SmartZone przez pole adresu IP

CVE-2025-46120CRITICAL9.8PL ✓same product

Path traversal w Ruckus Unleashed/ZoneDirector umożliwia RCE bez uwierzytelnienia

CVE-2025-46117CRITICAL9.1PL ✓same product

Command injection w CommScope Ruckus — wykonanie komend jako root przez CLI

CVE-2025-46121CRITICAL9.8PL ✓same product

Format string RCE w CommScope Ruckus Unleashed — nieuwierzytelniony dostęp