Vulnerability Intelligence Report
CVE-2025-46120
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates outside permitted directories, allowing a remote unauthenticated attacker who can upload a template (e.g., via FTP) to escalate privileges and run arbitrary template code on the controller.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:1.00%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-22 ↗CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| ruckuswireless | ruckus_unleashed | all |
| ruckuswireless | ruckus_zonedirector | all |
| commscope | ruckus_c110 | all |
| commscope | ruckus_e510 | all |
| commscope | ruckus_h320 | all |
| commscope | ruckus_h350 | all |
| commscope | ruckus_h510 | all |
| commscope | ruckus_h550 | all |
| commscope | ruckus_m510 | all |
| commscope | ruckus_m510-jp | all |
| commscope | ruckus_r310 | all |
| commscope | ruckus_r320 | all |
| commscope | ruckus_r350 | all |
| commscope | ruckus_r350e | all |
| commscope | ruckus_r510 | all |
| commscope | ruckus_r550 | all |
| commscope | ruckus_r560 | all |
| commscope | ruckus_r610 | all |
| commscope | ruckus_r650 | all |
| commscope | ruckus_r670 | all |
| commscope | ruckus_r710 | all |
| commscope | ruckus_r720 | all |
| commscope | ruckus_r730 | all |
| commscope | ruckus_r750 | all |
| commscope | ruckus_r760 | all |
| commscope | ruckus_r770 | all |
| commscope | ruckus_r850 | all |
| commscope | ruckus_t310c | all |
| commscope | ruckus_t310n | all |
| commscope | ruckus_t310s | all |
| commscope | ruckus_t350c | all |
| commscope | ruckus_t350d | all |
| commscope | ruckus_t350se | all |
| commscope | ruckus_t610 | all |
| commscope | ruckus_t670 | all |
| commscope | ruckus_t710 | all |
| commscope | ruckus_t710s | all |
| commscope | ruckus_t750 | all |
| commscope | ruckus_t750se | all |
| commscope | ruckus_t811-cm | all |
| commscope | ruckus_t811-cm_\(non-sfp\) | all |
| commscope | zonedirector_1200 | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.998%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2025-04-22T00:00:00 |
| Published | 2025-07-21T00:00:00 |
| Last Updated | 2025-07-23T17:18:49 |
Community Chatter & Buzz