Generated remediation guidance and an executive summary. No account required.
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates outside permitted directories, allowing a remote unauthenticated attacker who can upload a template (e.g., via FTP) to escalate privileges and run arbitrary template code on the controller.
Use CWE-22, Ruckuswireless vendor hub and Ruckus Unleashed product page to widen CVE-2025-46120 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-46121, CVE-2025-46122 and CVE-2025-46117 for nearby disclosures in the same product family.