Vulnerability Intelligence Report
CVE-2025-46122
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled input to the shell without adequate validation, enabling a remote attacker to specify a target by MAC address and execute arbitrary commands as root.
No Active Exploit Signals
CVSS Base Score
9.1
CRITICAL
Exploitability:2.3
Impact Score:6.1
EPSS Probability:1.12%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-77 ↗CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| ruckuswireless | ruckus_unleashed | all |
| ruckuswireless | ruckus_zonedirector | all |
| commscope | ruckus_c110 | all |
| commscope | ruckus_e510 | all |
| commscope | ruckus_h320 | all |
| commscope | ruckus_h350 | all |
| commscope | ruckus_h510 | all |
| commscope | ruckus_h550 | all |
| commscope | ruckus_m510 | all |
| commscope | ruckus_m510-jp | all |
| commscope | ruckus_r310 | all |
| commscope | ruckus_r320 | all |
| commscope | ruckus_r350 | all |
| commscope | ruckus_r350e | all |
| commscope | ruckus_r510 | all |
| commscope | ruckus_r550 | all |
| commscope | ruckus_r560 | all |
| commscope | ruckus_r610 | all |
| commscope | ruckus_r650 | all |
| commscope | ruckus_r670 | all |
| commscope | ruckus_r710 | all |
| commscope | ruckus_r720 | all |
| commscope | ruckus_r730 | all |
| commscope | ruckus_r750 | all |
| commscope | ruckus_r760 | all |
| commscope | ruckus_r770 | all |
| commscope | ruckus_r850 | all |
| commscope | ruckus_t310c | all |
| commscope | ruckus_t310n | all |
| commscope | ruckus_t310s | all |
| commscope | ruckus_t350c | all |
| commscope | ruckus_t350d | all |
| commscope | ruckus_t350se | all |
| commscope | ruckus_t610 | all |
| commscope | ruckus_t670 | all |
| commscope | ruckus_t710 | all |
| commscope | ruckus_t710s | all |
| commscope | ruckus_t750 | all |
| commscope | ruckus_t750se | all |
| commscope | ruckus_t811-cm | all |
| commscope | ruckus_t811-cm_\(non-sfp\) | all |
| commscope | zonedirector_1200 | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.120%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2025-04-22T00:00:00 |
| Published | 2025-07-21T00:00:00 |
| Last Updated | 2025-07-23T17:16:46 |
Community Chatter & Buzz