PoC Index

CVE-2025-46122

CRITICAL 9.1EPSS 1.1%

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled input to the shell without adequate validation, enabling a remote attacker to specify a target by MAC address and execute arbitrary commands as root.

CVSS v3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS
1.12% chance of exploitation in the next 30 days, 64th percentile
Published
2025-07-21
Updated
2025-07-23

Proof-of-concept exploits (1)

References

Related