CVE-2025-56086: Command Injection
OS Command Injection vulnerability in Ruijie RG-EW1200 EW3.0(1)B11P227EW120011130208RG-EW1200 V1.00 allowing attackers to execute arbitrary commands via a crafted POST request to the moduleget in file /usr/local/lua/devsta/networkConnect.lua.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-56086?
CVE-2025-56086 is classified as a critical severity vulnerability due to its potential for arbitrary command execution.
How do I fix CVE-2025-56086?
To fix CVE-2025-56086, update the Ruijie RG-EW1200 firmware to the latest version that addresses this vulnerability.
What types of attacks can CVE-2025-56086 enable?
CVE-2025-56086 enables attackers to execute arbitrary OS commands remotely, which can lead to full system compromise.
Who is affected by CVE-2025-56086?
CVE-2025-56086 affects users of the Ruijie RG-EW1200 router running the specified versions of the EW firmware.
What component is primarily responsible for CVE-2025-56086?
The vulnerability in CVE-2025-56086 resides in the 'module_get' function within the 'networkConnect.lua' file.