CVE-2025-46122: Command Injection
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint /admin/cmdstat.jsp passes attacker-controlled input to the shell without adequate validation, enabling a remote attacker to specify a target by MAC address and execute arbitrary commands as root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46122?
CVE-2025-46122 is rated as a high-severity vulnerability due to its potential for remote command execution through inadequate input validation.
How do I fix CVE-2025-46122?
To fix CVE-2025-46122, you should upgrade to CommScope Ruckus Unleashed versions 200.15.6.212.14 or 200.17.7.0.139 or later.
What systems are affected by CVE-2025-46122?
CVE-2025-46122 affects CommScope Ruckus Unleashed versions prior to 200.15.6.212.14 and 200.17.7.0.139.
What kind of attack can exploit CVE-2025-46122?
CVE-2025-46122 can be exploited by remote attackers who use malicious input to execute arbitrary commands on the system.
Is authentication required to exploit CVE-2025-46122?
Yes, CVE-2025-46122 requires the attacker to be authenticated to access the vulnerable diagnostics API endpoint.