Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-46121


An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to snprintf as the format string. A remote attacker can exploit this flaw either by sending a crafted request to the authenticated endpoint `/admin/_conf.jsp`, or without authentication and without direct network access to the controller by spoofing the MAC address of a favourite station and embedding malicious format specifiers in the DHCP hostname field, resulting in unauthenticated format-string processing and arbitrary code execution on the controller.


Published

2025-07-21T15:15:28.270

Last Modified

2025-08-05T17:18:43.993

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-134

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ruckuswireless ruckus_unleashed < 200.15.6.212.14 Yes
Application ruckuswireless ruckus_unleashed < 200.17.7.0.139 Yes
Application ruckuswireless ruckus_zonedirector < 10.5.1.0.279 Yes
Hardware commscope ruckus_c110 - No
Hardware commscope ruckus_e510 - No
Hardware commscope ruckus_h320 - No
Hardware commscope ruckus_h350 - No
Hardware commscope ruckus_h510 - No
Hardware commscope ruckus_h550 - No
Hardware commscope ruckus_m510 - No
Hardware commscope ruckus_m510-jp - No
Hardware commscope ruckus_r310 - No
Hardware commscope ruckus_r320 - No
Hardware commscope ruckus_r350 - No
Hardware commscope ruckus_r350e - No
Hardware commscope ruckus_r510 - No
Hardware commscope ruckus_r550 - No
Hardware commscope ruckus_r560 - No
Hardware commscope ruckus_r610 - No
Hardware commscope ruckus_r650 - No
Hardware commscope ruckus_r670 - No
Hardware commscope ruckus_r710 - No
Hardware commscope ruckus_r720 - No
Hardware commscope ruckus_r730 - No
Hardware commscope ruckus_r750 - No
Hardware commscope ruckus_r760 - No
Hardware commscope ruckus_r770 - No
Hardware commscope ruckus_r850 - No
Hardware commscope ruckus_t310c - No
Hardware commscope ruckus_t310n - No
Hardware commscope ruckus_t310s - No
Hardware commscope ruckus_t350c - No
Hardware commscope ruckus_t350d - No
Hardware commscope ruckus_t350se - No
Hardware commscope ruckus_t610 - No
Hardware commscope ruckus_t670 - No
Hardware commscope ruckus_t710 - No
Hardware commscope ruckus_t710s - No
Hardware commscope ruckus_t750 - No
Hardware commscope ruckus_t750se - No
Hardware commscope ruckus_t811-cm - No
Hardware commscope ruckus_t811-cm_\(non-sfp\) - No
Hardware commscope zonedirector_1200 - No

References