CVE-2025-56077: Command Injection
Published Dec 11, 2025
·Updated
OS Command Injection vulnerability in Ruijie RG-RAP2200(E) 247 2200 allowing attackers to execute arbitrary commands via a crafted POST request to the moduleset in file /usr/local/lua/devsta/nbrcwmp.lua.
Affected Software
7 affected components
Ruijie RG-RAP2200(E)
All of the following
Ruijienetworks Reyee Os=2.280.0
Ruijie Rg-eap162\(g\)
All of the following
Ruijienetworks Reyee Os=2.280.0
Ruijie Rg-rap1260
All of the following
Ruijie Rg-rap2200\(e\) Firmware=3.0\(1\)b11p247
Ruijie Rg-rap2200\(e\)
Event History
Dec 11, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56077?
CVE-2025-56077 is classified as a high-severity OS Command Injection vulnerability.
2
How do I fix CVE-2025-56077?
To fix CVE-2025-56077, update the Ruijie RG-RAP2200(E) to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2025-56077?
CVE-2025-56077 affects users of the Ruijie RG-RAP2200(E) device.
4
What is the impact of exploiting CVE-2025-56077?
Exploiting CVE-2025-56077 allows attackers to execute arbitrary commands on the affected device.
5
What actions should I take if I am vulnerable to CVE-2025-56077?
If vulnerable to CVE-2025-56077, implement the recommended updates immediately and review security practices.