Vulnerability Intelligence Report
CVE-2025-46123
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where the authenticated configuration endpoint `/admin/_conf.jsp` writes the Wi-Fi guest password to memory with snprintf using the attacker-supplied value as the format string; a crafted password therefore triggers uncontrolled format-string processing and enables remote code execution on the controller.
No Active Exploit Signals
CVSS Base Score
7.2
HIGH
Exploitability:1.3
Impact Score:5.9
EPSS Probability:1.09%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-134 ↗CWE-134 Use of Externally-Controlled Format String
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| ruckuswireless | ruckus_unleashed | all |
| ruckuswireless | ruckus_zonedirector | all |
| commscope | ruckus_c110 | all |
| commscope | ruckus_e510 | all |
| commscope | ruckus_h320 | all |
| commscope | ruckus_h350 | all |
| commscope | ruckus_h510 | all |
| commscope | ruckus_h550 | all |
| commscope | ruckus_m510 | all |
| commscope | ruckus_m510-jp | all |
| commscope | ruckus_r310 | all |
| commscope | ruckus_r320 | all |
| commscope | ruckus_r350 | all |
| commscope | ruckus_r350e | all |
| commscope | ruckus_r510 | all |
| commscope | ruckus_r550 | all |
| commscope | ruckus_r560 | all |
| commscope | ruckus_r610 | all |
| commscope | ruckus_r650 | all |
| commscope | ruckus_r670 | all |
| commscope | ruckus_r710 | all |
| commscope | ruckus_r720 | all |
| commscope | ruckus_r730 | all |
| commscope | ruckus_r750 | all |
| commscope | ruckus_r760 | all |
| commscope | ruckus_r770 | all |
| commscope | ruckus_r850 | all |
| commscope | ruckus_t310c | all |
| commscope | ruckus_t310n | all |
| commscope | ruckus_t310s | all |
| commscope | ruckus_t350c | all |
| commscope | ruckus_t350d | all |
| commscope | ruckus_t350se | all |
| commscope | ruckus_t610 | all |
| commscope | ruckus_t670 | all |
| commscope | ruckus_t710 | all |
| commscope | ruckus_t710s | all |
| commscope | ruckus_t750 | all |
| commscope | ruckus_t750se | all |
| commscope | ruckus_t811-cm | all |
| commscope | ruckus_t811-cm_\(non-sfp\) | all |
| commscope | zonedirector_1200 | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.091%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2025-04-22T00:00:00 |
| Published | 2025-07-21T00:00:00 |
| Last Updated | 2025-07-24T20:25:38 |
Community Chatter & Buzz