OS Command Injection Vulnerability in Ruijie RG-EW3000GX
CVE-2026-92397
Key Information:
- Vendor
Ruijie
- Status
- Vendor
- CVE Published:
- 16 September 2026
Badges
What is CVE-2026-92397?
A security flaw has been identified in the Ruijie RG-EW3000GX, specifically within the cc_set function of the unifyframe-sgi.elf component, where improperly validated input allows attackers to inject operating system commands. This command injection vulnerability enables remote exploitation, potentially compromising system integrity or facilitating unauthorized access. It has been publicly disclosed and poses a significant threat to affected systems.
Affected Version(s)
RG-EW3000GX EW_3.0(1)B11P380
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
