CVE-2025-56079: Command Injection
Published Dec 11, 2025
·Updated
OS Command Injection vulnerability in Ruijie RG-EW1300G EW1300G V1.00/V2.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the moduleget in file /usr/local/lua/devsta/networkConnect.lua.
Affected Software
7 affected components
Ruijie RG-EW1300G>=V1.00<=V4.00
All of the following
Ruijie Rg-ew1300g Firmware
Any of the following
Ruijie RG-EW1300G=1.0
Ruijie RG-EW1300G=2.0
Ruijie RG-EW1300G=4.0
All of the following
Ruijie Be50 Firmware=ew_3.0\(1\)b11p258
Ruijie Be50
Event History
Dec 11, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56079?
CVE-2025-56079 has a high severity level due to its exploitation potential for OS command injection.
2
How do I fix CVE-2025-56079?
To fix CVE-2025-56079, update the Ruijie RG-EW1300G to the latest firmware version that addresses this vulnerability.
3
What systems are affected by CVE-2025-56079?
CVE-2025-56079 affects Ruijie RG-EW1300G versions V1.00, V2.00, and V4.00.
4
What type of vulnerability is CVE-2025-56079?
CVE-2025-56079 is classified as an OS Command Injection vulnerability.
5
Can CVE-2025-56079 be exploited remotely?
Yes, CVE-2025-56079 can be exploited remotely via a crafted POST request.