CVE-2025-56082: Command Injection
Published Dec 11, 2025
·Updated
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the checkchanges in file /usr/lib/lua/luci/controller/admin/common.lua.
Affected Software
3 affected components
Ruijie RG-BCR600W
All of the following
Ruijie Rg-bcr600w Firmware
Ruijie RG-BCR600W
Event History
Dec 11, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56082?
CVE-2025-56082 has a high severity due to its potential to allow attackers to execute arbitrary commands.
2
How do I fix CVE-2025-56082?
To fix CVE-2025-56082, apply the latest firmware update provided by Ruijie for the RG-BCR600W device.
3
What kind of attacks can CVE-2025-56082 enable?
CVE-2025-56082 can enable attackers to execute arbitrary OS commands, potentially compromising the device and network.
4
Which devices are affected by CVE-2025-56082?
CVE-2025-56082 affects the Ruijie RG-BCR600W and its firmware versions.
5
What type of vulnerability is CVE-2025-56082?
CVE-2025-56082 is classified as an OS Command Injection vulnerability.