Generated remediation guidance and an executive summary. No account required.
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remote attacker to upload or retrieve arbitrary files from writable firmware directories and thereby expose sensitive information or compromise the controller.
Use CWE-284, Ruckuswireless vendor hub and Ruckus Unleashed product page to widen CVE-2025-46118 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-46121, CVE-2025-46120 and CVE-2025-46122 for nearby disclosures in the same product family.