OS Command Injection Vulnerability in Ruijie RG-EW1800GX Devices
CVE-2025-56106
8.8HIGH
What is CVE-2025-56106?
An OS Command Injection vulnerability exists in the Ruijie RG-EW1800GX device, specifically in the module_set function located in /usr/local/lua/dev_sta/nbr_cwmp.lua. This flaw enables attackers to execute arbitrary commands by sending a specially crafted POST request, potentially compromising the device’s integrity and security. Organizations using this product must take immediate steps to mitigate the risk associated with this vulnerability.
