Ruckuswireless Ruckus Unleashed vulnerabilities
9 known vulnerabilities affecting ruckuswireless/ruckus_unleashed.
Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH2MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2025-46121P2CRITICALCVSS 9.8fixed in 200.15.6.212.14≥ 200.17, < 200.17.7.0.1392025-07-21
CVE-2025-46121 [CRITICAL] CWE-134 CVE-2025-46121: An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, w
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to snprintf as the format string. A remote attacker can exploit this flaw either by sending a crafted request to the authenticated e
nvd
CVE-2025-46120P2CRITICALCVSS 9.8fixed in 200.15.6.212.14≥ 200.17, < 200.17.7.0.1392025-07-21
CVE-2025-46120 [CRITICAL] CWE-22 CVE-2025-46120: An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, a
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates outside permitted directories, allowing a remote unauthenticated attacker who can upload a templ
nvd
CVE-2025-46122P3CRITICALCVSS 9.1fixed in 200.15.6.212.14≥ 200.17, < 200.17.7.0.1392025-07-21
CVE-2025-46122 [CRITICAL] CWE-77 CVE-2025-46122: An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, w
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled input to the shell without adequate validation, enabling a remote attacker to specify a target by MAC address and execute arbitrary commands as root.
nvd
CVE-2025-46117P3CRITICALCVSS 9.1fixed in 200.15.6.212.14≥ 200.17, < 200.17.7.0.1392025-07-21
CVE-2025-46117 [CRITICAL] CWE-78 CVE-2025-46117: An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, a
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where a hidden debug script `.ap_debug.sh` invoked from the restricted CLI does not properly sanitize its input, allowing an authenticated attacker to execute arbitrary commands as root on the controll
nvd
CVE-2025-46116P3HIGHCVSS 8.8fixed in 200.15.6.212.14≥ 200.17, < 200.17.7.0.1392025-07-21
CVE-2025-46116 [HIGH] CWE-250 CVE-2025-46116: An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, a
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the passphrase requirement for a hidden CLI command `!v54!` via a management API call and then invoke it to escape the restricted shell and obtain a root shell
nvd
CVE-2025-46123P3HIGHCVSS 7.2fixed in 200.15.6.212.14≥ 200.17, < 200.17.7.0.1392025-07-21
CVE-2025-46123 [HIGH] CWE-134 CVE-2025-46123: An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, a
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where the authenticated configuration endpoint `/admin/_conf.jsp` writes the Wi-Fi guest password to memory with snprintf using the attacker-supplied value as the format string; a crafted password therefo
nvd
CVE-2025-46119P3MEDIUMCVSS 6.3fixed in 200.15.6.212.14≥ 200.17, < 200.17.7.0.1392025-07-21
CVE-2025-46119 [MEDIUM] CWE-555 CVE-2025-46119: An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, a
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where an authenticated request to the management endpoint `/admin/_cmdstat.jsp` discloses the administrator password in a trivially reversible obfuscated form. The same obfuscation method persists in co
nvd
CVE-2025-46118P4MEDIUMCVSS 5.3fixed in 200.15.6.212.14≥ 200.17, < 200.17.7.0.1392025-07-21
CVE-2025-46118 [MEDIUM] CWE-284 CVE-2025-46118: An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 an
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remote attacker to upload or retrieve arbitrary files from writable firmware directories and thereby
nvd
CVE-2025-63735P4MEDIUMCVSS 6.1v200.13.6.1.3192025-11-25
CVE-2025-63735 [MEDIUM] CWE-79 CVE-2025-63735: A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name
A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp.
nvd