CVE-2025-46119: Medium severity CommScope Ruckus Unleashed vulnerability
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where an authenticated request to the management endpoint /admin/cmdstat.jsp discloses the administrator password in a trivially reversible obfuscated form. The same obfuscation method persists in configuration prior to 200.18.7.1.302, allowing anyone who obtains the system configuration to recover the plaintext credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46119?
CVE-2025-46119 is considered a high severity vulnerability due to its potential to expose sensitive administrator credentials.
How do I fix CVE-2025-46119?
To fix CVE-2025-46119, update CommScope Ruckus Unleashed to version 200.15.6.12.304 or later.
What impacts does CVE-2025-46119 have on Ruckus equipment?
CVE-2025-46119 allows authenticated users to retrieve the administrator password in a reversible obfuscated form, compromising the security of the device.
Which versions of Ruckus software are affected by CVE-2025-46119?
Affected versions of Ruckus software include CommScope Ruckus Unleashed prior to 200.15.6.12.304 and Ruckus ZoneDirector prior to 10.5.1.0.282.
Is CVE-2025-46119 a remote vulnerability?
CVE-2025-46119 requires authenticated access, so it is not classified as a remote vulnerability.