CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.1. It may be remotely exploitable.
CVE
CVE-2025-46122
Severity
CRITICAL
CVSS
9.1
EPSS
1.12%
Original NVD Description
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled input to the shell without adequate validation, enabling a remote attacker to specify a target by MAC address and execute arbitrary commands as root.
Related CVEs
Other vulnerabilities affecting the same vendor(s)