CVE-2025-46116
8.8CommScope · Ruckus Unleashed and ZoneDirector
CommScope Ruckus devices contain a vulnerability allowing authenticated attackers to bypass CLI passphrase requirements and gain root shell access via a management API call.
Executive summary
Authenticated attackers can achieve full root-level compromise of CommScope Ruckus network controllers by exploiting a command injection flaw in the management API.
Vulnerability
This vulnerability involves a flaw where an authenticated attacker can disable passphrase requirements for a hidden CLI command, allowing them to escape the restricted shell and execute arbitrary commands with root privileges.
Business impact
A successful exploit grants the attacker total control over the network controller, which is a critical piece of infrastructure. This level of access could lead to full network compromise, interception of sensitive traffic, and severe disruption of business communications. With a CVSS score of 8.8, this vulnerability represents a high risk to organizational security and operational integrity.
Remediation
Immediate Action: Update Ruckus Unleashed and ZoneDirector firmware to the versions specified in the vendor security bulletin to resolve the underlying command injection flaw.
Proactive Monitoring: Audit management API logs for suspicious requests or unusual CLI activity, specifically looking for interactions with the !v54! command.
Compensating Controls: Restrict access to the management interface to authorized administrative IP addresses only, effectively limiting the potential attacker pool to trusted internal sources.
Exploitation status
Public Exploit Available: Yes, a published proof of concept exists, attributed to the technical write-up provided by Computest.
Analyst recommendation
Given the potential for full system compromise, organizations using affected Ruckus hardware must prioritize patching these devices immediately. Administrators should review the vendor documentation to ensure all controllers are updated beyond the vulnerable thresholds, as this vulnerability provides a direct path for attackers to gain persistent, elevated access to the network environment.