CVE-2025-46117: OS Command Injection
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where a hidden debug script .apdebug.sh invoked from the restricted CLI does not properly sanitize its input, allowing an authenticated attacker to execute arbitrary commands as root on the controller or specified target.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46117?
CVE-2025-46117 has a medium severity rating due to input sanitization issues that can be exploited by authenticated attackers.
How do I fix CVE-2025-46117?
To fix CVE-2025-46117, upgrade to CommScope Ruckus Unleashed version 200.15.6.212.14 or 200.17.7.0.139, or Ruckus ZoneDirector version 10.5.1.0.279 or later.
What types of devices are affected by CVE-2025-46117?
CVE-2025-46117 affects CommScope Ruckus Unleashed and Ruckus ZoneDirector devices prior to specified versions.
Can CVE-2025-46117 be exploited remotely?
No, CVE-2025-46117 requires authenticated access, which means it cannot be exploited remotely without valid credentials.
What are the potential consequences of CVE-2025-46117?
The consequences of CVE-2025-46117 include the possibility of unauthorized access or execution of arbitrary commands by authenticated users.