CVE-2025-56088: Command Injection
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the actionservice in file /usr/lib/lua/luci/controller/admin/service.lua.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-56088?
CVE-2025-56088 is classified as a high severity vulnerability due to its potential for arbitrary command execution.
How do I fix CVE-2025-56088?
To address CVE-2025-56088, ensure you update the firmware of the Ruijie RG-BCR860 to the latest version provided by the vendor.
What types of attacks can exploit CVE-2025-56088?
CVE-2025-56088 can be exploited through a crafted POST request that allows attackers to inject and execute arbitrary commands.
Which devices are affected by CVE-2025-56088?
The Ruijie RG-BCR860 is affected by CVE-2025-56088 if it is running an unpatched version of its firmware.
Is CVE-2025-56088 easy to exploit?
Yes, CVE-2025-56088 is considered easy to exploit due to the straightforward nature of the command injection through HTTP requests.