CVE-2025-46121
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to snprintf as the format string. A remote attacker can exploit this flaw either by sending a crafted request to the authenticated endpoint `/admin/_conf.jsp`, or without authentication and without direct network access to the controller by spoofing the MAC address of a favourite station and embedding malicious format specifiers in the DHCP hostname field, resulting in unauthenticated format-string processing and arbitrary code execution on the controller.
Affected (3)
Products: Ruckuswireless: Ruckus Unleashed, Ruckus Zonedirector
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 200.15.6.212.14 | |
| Before 10.5.1.0.279 |
| Running on/with | Platform Versions |
|---|---|
Commscope Ruckus C110 | All versions |
Commscope Ruckus E510 | All versions |
Commscope Ruckus H320 | All versions |
Commscope Ruckus H350 | All versions |
Commscope Ruckus H510 | All versions |
Commscope Ruckus H550 | All versions |
Commscope Ruckus M510 | All versions |
Commscope Ruckus M510 Jp | All versions |
Commscope Ruckus R310 | All versions |
Commscope Ruckus R320 | All versions |
Commscope Ruckus R350 | All versions |
Commscope Ruckus R350e | All versions |
Commscope Ruckus R510 | All versions |
Commscope Ruckus R550 | All versions |
Commscope Ruckus R560 | All versions |
Commscope Ruckus R610 | All versions |
Commscope Ruckus R650 | All versions |
Commscope Ruckus R670 | All versions |
Commscope Ruckus R710 | All versions |
Commscope Ruckus R720 | All versions |
Commscope Ruckus R730 | All versions |
Commscope Ruckus R750 | All versions |
Commscope Ruckus R760 | All versions |
Commscope Ruckus R770 | All versions |
Commscope Ruckus R850 | All versions |
Commscope Ruckus T310c | All versions |
Commscope Ruckus T310n | All versions |
Commscope Ruckus T310s | All versions |
Commscope Ruckus T350c | All versions |
Commscope Ruckus T350d | All versions |
Commscope Ruckus T350se | All versions |
Commscope Ruckus T610 | All versions |
Commscope Ruckus T670 | All versions |
Commscope Ruckus T710 | All versions |
Commscope Ruckus T710s | All versions |
Commscope Ruckus T750 | All versions |
Commscope Ruckus T750se | All versions |
Commscope Ruckus T811 Cm | All versions |
Commscope Ruckus T811 Cm (non Sfp) | All versions |
Commscope Zonedirector 1200 | All versions |
References (2)
Source: cve@mitre.org
ExploitThird Party Advisory
Timeline
No history available yet.