Unrated severityNVD Advisory· Published Jul 21, 2025· Updated Jul 23, 2025
CVE-2025-46122
CVE-2025-46122
Description
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint /admin/_cmdstat.jsp passes attacker-controlled input to the shell without adequate validation, enabling a remote attacker to specify a target by MAC address and execute arbitrary commands as root.
Affected products
2- CommScope/Ruckus Unleasheddescription
- Range: prior to 200.15.6.212.14 and 200.17.7.0.139
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.