Security Advisory

CVE-2025-46118

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-21 00:00:00
Last updated 2025-07-28 19:37:41
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remote attacker to upload or retrieve arbitrary files from writable firmware directories and thereby expose sensitive information or compromise the controller.