CVE-2025-46118

MEDIUM
Published Jul 21, 2025 Modified Aug 5, 2025 CWE-284

Description

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remote attacker to upload or retrieve arbitrary files from writable firmware directories and thereby expose sensitive information or compromise the controller.

Is your site exposed to CVE-2025-46118?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

5.3
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Weakness Type (CWE)

CWE-284 CWE-284

Affected Products

Vendor Product
ruckuswireless ruckus_unleashed
ruckuswireless ruckus_unleashed
ruckuswireless ruckus_zonedirector
commscope ruckus_c110
commscope ruckus_e510
commscope ruckus_h320
commscope ruckus_h350
commscope ruckus_h510
commscope ruckus_h550
commscope ruckus_m510
commscope ruckus_m510-jp
commscope ruckus_r310
commscope ruckus_r320
commscope ruckus_r350
commscope ruckus_r350e
commscope ruckus_r510
commscope ruckus_r550
commscope ruckus_r560
commscope ruckus_r610
commscope ruckus_r650
commscope ruckus_r670
commscope ruckus_r710
commscope ruckus_r720
commscope ruckus_r730
commscope ruckus_r750
commscope ruckus_r760
commscope ruckus_r770
commscope ruckus_r850
commscope ruckus_t310c
commscope ruckus_t310n
commscope ruckus_t310s
commscope ruckus_t350c
commscope ruckus_t350d
commscope ruckus_t350se
commscope ruckus_t610
commscope ruckus_t670
commscope ruckus_t710
commscope ruckus_t710s
commscope ruckus_t750
commscope ruckus_t750se
commscope ruckus_t811-cm
commscope ruckus_t811-cm_\(non-sfp\)
commscope zonedirector_1200

References

Frequently Asked Questions

What is CVE-2025-46118? +
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remote attacker to upload or retrieve arbitrary files from writable firmware directories and thereby expose sensitive information or compromise the controller. It has a CVSS v3.1 base score of 5.3 (MEDIUM).
How severe is CVE-2025-46118? +
CVE-2025-46118 has a CVSS v3.1 score of 5.3 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2025-46118? +
CVE-2025-46118 affects products from commscope, ruckuswireless, specifically: ruckus_c110, ruckus_e510, ruckus_h320, ruckus_h350, ruckus_h510, ruckus_h550, ruckus_m510, ruckus_m510-jp, ruckus_r310, ruckus_r320, ruckus_r350, ruckus_r350e, ruckus_r510, ruckus_r550, ruckus_r560, ruckus_r610, ruckus_r650, ruckus_r670, ruckus_r710, ruckus_r720, ruckus_r730, ruckus_r750, ruckus_r760, ruckus_r770, ruckus_r850, ruckus_t310c, ruckus_t310n, ruckus_t310s, ruckus_t350c, ruckus_t350d, ruckus_t350se, ruckus_t610, ruckus_t670, ruckus_t710, ruckus_t710s, ruckus_t750, ruckus_t750se, ruckus_t811-cm, ruckus_t811-cm_\(non-sfp\), ruckus_unleashed, ruckus_zonedirector, zonedirector_1200. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2025-46118? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2025-46118 — free, no signup required.