CVE Vulnerabilities

CVE-2025-46119

J2EE Misconfiguration: Plaintext Password in Configuration File

Published: Jul 21, 2025 | Modified: Aug 05, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where an authenticated request to the management endpoint /admin/_cmdstat.jsp discloses the administrator password in a trivially reversible obfuscated form. The same obfuscation method persists in configuration prior to 200.18.7.1.302, allowing anyone who obtains the system configuration to recover the plaintext credentials.

Weakness

The J2EE application stores a plaintext password in a configuration file.

Affected Software

Name Vendor Start Version End Version
Ruckus_unleashed Ruckuswireless * 200.15.6.212.14 (excluding)
Ruckus_unleashed Ruckuswireless 200.17 (including) 200.17.7.0.139 (excluding)
Ruckus_zonedirector Ruckuswireless * 10.5.1.0.279 (excluding)

Potential Mitigations

References