OS Command Injection in Ruijie X30-PRO Devices
CVE-2025-56117
8.8HIGH
What is CVE-2025-56117?
An OS Command Injection vulnerability was discovered in Ruijie X30-PRO devices, specifically in the module_set function within the nbr_cwmp.lua file. This vulnerability allows attackers to execute arbitrary commands via specially crafted POST requests. If exploited, it could lead to unauthorized access and manipulation of the device's system, posing significant security risks to networks utilizing these devices.
