CVE-2025-46123: High severity CommScope Ruckus Unleashed vulnerability
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where the authenticated configuration endpoint /admin/conf.jsp writes the Wi-Fi guest password to memory with snprintf using the attacker-supplied value as the format string; a crafted password therefore triggers uncontrolled format-string processing and enables remote code execution on the controller.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46123?
CVE-2025-46123 is rated as a high severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2025-46123?
To fix CVE-2025-46123, update CommScope Ruckus Unleashed to versions 200.15.6.212.14 or 200.17.7.0.139, or Ruckus ZoneDirector to version 10.5.1.0.279 or later.
What are the affected products for CVE-2025-46123?
CVE-2025-46123 affects CommScope Ruckus Unleashed prior to version 200.15.6.212.14 and 200.17.7.0.139, as well as Ruckus ZoneDirector before version 10.5.1.0.279.
What kind of attack does CVE-2025-46123 enable?
CVE-2025-46123 potentially allows attackers to exploit an authenticated configuration endpoint, enabling them to access stored guest Wi-Fi passwords.
Is CVE-2025-46123 remote exploitable?
CVE-2025-46123 requires authentication to exploit, which limits its remote exploitability to already authenticated users.