CVE-2025-46120 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a pat…
Critical CVSS: 9.8

CVE-2025-46120

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates outside permitted directories, allowing a remote unauthenticated attacker who can upload a template (e.g., via FTP) to escalate privileges and run arbitrary template code on the controller.
Vendor
Ruckuswireless
Product
Ruckus Unleashed
CWE
CWE-22
Yayın Tarihi
2025-07-21 15:15:28
Güncelleme
2025-08-05 17:18:32
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar