CVE-2025-46118: Medium severity CommScope Ruckus Unleashed vulnerability
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remote attacker to upload or retrieve arbitrary files from writable firmware directories and thereby expose sensitive information or compromise the controller.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46118?
CVE-2025-46118 has a high severity rating due to the presence of hard-coded credentials that can be exploited by remote attackers.
How do I fix CVE-2025-46118?
To fix CVE-2025-46118, update CommScope Ruckus Unleashed to version 200.15.6.212.14 or 200.17.7.0.139, or Ruckus ZoneDirector to version 10.5.1.0.279 or later.
What impact does CVE-2025-46118 have on Ruckus devices?
CVE-2025-46118 allows remote attackers to gain unauthorized FTP access, potentially leading to unauthorized file uploads and data retrieval.
Is my version of Ruckus Unleashed affected by CVE-2025-46118?
Ruckus Unleashed versions prior to 200.15.6.212.14 and 200.17.7.0.139 are affected by CVE-2025-46118.
What are the affected versions for Ruckus ZoneDirector in CVE-2025-46118?
Ruckus ZoneDirector versions prior to 10.5.1.0.279 are impacted by CVE-2025-46118.