OS Command Injection in Ruijie RG-EW1200 by Ruijie
CVE-2025-56086
8.8HIGH
What is CVE-2025-56086?
The Ruijie RG-EW1200 device is susceptible to an OS Command Injection vulnerability that allows attackers to execute arbitrary commands. This exploitation can occur through a specially crafted POST request targeting the module_get function in the networkConnect.lua file located at /usr/local/lua/dev_sta/. Such vulnerabilities can enable unauthorized access and compromise network integrity, making it crucial for users to apply patches and enhance their security configurations to mitigate potential risks.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
