CVE-2025-56085: Command Injection
OS Command Injection vulnerability in Ruijie RG-EW1200 EW3.0(1)B11P227EW120011130208RG-EW1200 V1.00 allowing attackers to execute arbitrary commands via a crafted POST request to the moduleset in file /usr/local/lua/devconfig/configretain.lua.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-56085?
CVE-2025-56085 is classified as a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2025-56085?
To fix CVE-2025-56085, you should apply the latest firmware updates provided by Ruijie that address this vulnerability.
What systems are affected by CVE-2025-56085?
CVE-2025-56085 affects Ruijie RG-EW1200 devices running firmware versions prior to the security patch.
What type of vulnerability is CVE-2025-56085?
CVE-2025-56085 is an OS Command Injection vulnerability that allows arbitrary command execution via crafted POST requests.
What can attackers do with CVE-2025-56085?
Attackers can execute arbitrary system commands on the infected Ruijie RG-EW1200 device, potentially gaining unauthorized access or control.