CVE-2025-46116

HIGH

CommScope Ruckus Unleashed <200.15.6.212.14, 200.17.7.0.139 - Privi...

Title source: llm
STIX 2.1

Description

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the passphrase requirement for a hidden CLI command `!v54!` via a management API call and then invoke it to escape the restricted shell and obtain a root shell on the controller.

Scores

CVSS v3 8.8
EPSS 0.0009
EPSS Percentile 25.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-269 CWE-250
Status published
Products (2)
ruckuswireless/ruckus_unleashed < 200.15.6.212.14
ruckuswireless/ruckus_zonedirector < 10.5.1.0.279
Published Jul 21, 2025
Tracked Since Feb 18, 2026