OS Command Injection Vulnerability in Ruijie RG-BCR600W
CVE-2025-56127
8.8HIGH
What is CVE-2025-56127?
The Ruijie RG-BCR600W is vulnerable to an OS Command Injection flaw that allows malicious actors to execute arbitrary commands. This vulnerability can be exploited by sending a specially crafted POST request to the 'get_wanobj' endpoint located in '/usr/lib/lua/luci/controller/admin/common.lua'. Attackers could leverage this weakness to compromise the device, leading to unauthorized command execution and potential breach of the network's integrity.
