CVE-2025-46117
8.8CommScope · Ruckus Unleashed and Ruckus ZoneDirector
A command injection vulnerability in CommScope Ruckus products allows authenticated attackers to execute arbitrary commands as root via an unsanitized debug script.
Executive summary
A high-severity command injection vulnerability in CommScope Ruckus networking hardware enables authenticated attackers to gain root-level control over the controller.
Vulnerability
The flaw resides in a hidden debug script, .ap_debug.sh, which is accessible from the restricted CLI. An authenticated attacker can leverage this script to inject and execute arbitrary commands with root privileges.
Business impact
The vulnerability carries a CVSS score of 8.8, indicating a high risk to organizational infrastructure. Successful exploitation grants an attacker full administrative control over the affected network controller, potentially leading to total network compromise, data exfiltration, and the ability to pivot into internal segments.
Remediation
Immediate Action: Update Ruckus Unleashed firmware to version 200.15.6.212.14 or 200.17.7.0.139, and update Ruckus ZoneDirector firmware to version 10.5.1.0.279 or later.
Proactive Monitoring: Monitor CLI access logs for suspicious command patterns or unauthorized attempts to access debug-related files or scripts.
Compensating Controls: Restrict access to the management CLI to only authorized administrative personnel and ensure that internal management interfaces are not reachable from untrusted network segments.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up provided by Computest.
Analyst recommendation
Given the potential for complete system takeover and the availability of a public proof-of-concept, this vulnerability poses a significant risk to network integrity. Security teams should prioritize the application of the vendor-supplied firmware updates across all affected Ruckus controllers immediately to eliminate the command injection vector.