ZeroHour

CVE-2025-46116

PoC
CVSS 3.1
8.8 high
EPSS
<1%p42
Published
()
Modified
Description

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the passphrase requirement for a hidden CLI command `!v54!` via a management API call and then invoke it to escape the restricted shell and obtain a root shell on the controller.

Vendors
ruckuswireless
Products
ruckus unleashed, ruckus zonedirector
Weakness
CWE-250, CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.