CVE-2025-56087: Command Injection
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the runtcpdump in file /usr/lib/lua/luci/controller/admin/commontcpdump.lua.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-56087?
CVE-2025-56087 is considered a high severity vulnerability due to its potential for allowing remote command execution.
How do I fix CVE-2025-56087?
To fix CVE-2025-56087, you should apply the latest firmware update provided by Ruijie for the RG-BCR600W device.
What are the implications of CVE-2025-56087 for Ruijie RG-BCR600W users?
Users of Ruijie RG-BCR600W are at risk of unauthorized access and control over their devices due to this OS command injection vulnerability.
Can CVE-2025-56087 be exploited remotely?
Yes, CVE-2025-56087 can be exploited remotely via a specially crafted POST request to the vulnerable endpoint.
Is there a workaround for CVE-2025-56087 if I cannot update my device?
If an update is not possible, it is advised to restrict access to the administrative interface of the RG-BCR600W to trusted IP addresses only.