CVE-2025-46116: High severity CommScope Ruckus Unleashed vulnerability
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the passphrase requirement for a hidden CLI command !v54! via a management API call and then invoke it to escape the restricted shell and obtain a root shell on the controller.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46116?
CVE-2025-46116 is rated as a medium severity vulnerability due to the potential for authenticated attackers to disable security features.
How do I fix CVE-2025-46116?
To fix CVE-2025-46116, update Ruckus Unleashed to version 200.15.6.212.14 or later, and Ruckus ZoneDirector to version 10.5.1.0.279 or later.
Who is affected by CVE-2025-46116?
CVE-2025-46116 affects users of Ruckus Unleashed prior to version 200.15.6.212.14 and Ruckus ZoneDirector prior to version 10.5.1.0.279.
What is the impact of CVE-2025-46116?
The impact of CVE-2025-46116 allows authenticated attackers to disable passphrase requirements for privileged commands, potentially compromising the device management.
Is CVE-2025-46116 remotely exploitable?
CVE-2025-46116 requires authenticated access, so it is not remotely exploitable without valid user credentials.