CVE-2025-46119
MEDIUMDescription
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where an authenticated request to the management endpoint `/admin/_cmdstat.jsp` discloses the administrator password in a trivially reversible obfuscated form. The same obfuscation method persists in configuration prior to 200.18.7.1.302, allowing anyone who obtains the system configuration to recover the plaintext credentials.
Is your site exposed to CVE-2025-46119?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ruckuswireless | ruckus_unleashed |
| ruckuswireless | ruckus_unleashed |
| ruckuswireless | ruckus_zonedirector |
| commscope | ruckus_c110 |
| commscope | ruckus_e510 |
| commscope | ruckus_h320 |
| commscope | ruckus_h350 |
| commscope | ruckus_h510 |
| commscope | ruckus_h550 |
| commscope | ruckus_m510 |
| commscope | ruckus_m510-jp |
| commscope | ruckus_r310 |
| commscope | ruckus_r320 |
| commscope | ruckus_r350 |
| commscope | ruckus_r350e |
| commscope | ruckus_r510 |
| commscope | ruckus_r550 |
| commscope | ruckus_r560 |
| commscope | ruckus_r610 |
| commscope | ruckus_r650 |
| commscope | ruckus_r670 |
| commscope | ruckus_r710 |
| commscope | ruckus_r720 |
| commscope | ruckus_r730 |
| commscope | ruckus_r750 |
| commscope | ruckus_r760 |
| commscope | ruckus_r770 |
| commscope | ruckus_r850 |
| commscope | ruckus_t310c |
| commscope | ruckus_t310n |
| commscope | ruckus_t310s |
| commscope | ruckus_t350c |
| commscope | ruckus_t350d |
| commscope | ruckus_t350se |
| commscope | ruckus_t610 |
| commscope | ruckus_t670 |
| commscope | ruckus_t710 |
| commscope | ruckus_t710s |
| commscope | ruckus_t750 |
| commscope | ruckus_t750se |
| commscope | ruckus_t811-cm |
| commscope | ruckus_t811-cm_\(non-sfp\) |
| commscope | zonedirector_1200 |
References
Frequently Asked Questions
What is CVE-2025-46119? +
How severe is CVE-2025-46119? +
What products are affected by CVE-2025-46119? +
How do I check if I'm vulnerable to CVE-2025-46119? +
Related Vulnerabilities
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, …
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass …
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, …
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` …
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, …
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, …