CVE-2025-56089: Command Injection
OS Command Injection vulnerability in Ruijie M18 EW3.0(1)B11P226M1810223116 allowing attackers to execute arbitrary commands via a crafted POST request to the moduleset in file /usr/local/lua/devsta/nbrcwmp.lua.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-56089?
The severity of CVE-2025-56089 is considered critical due to the potential for arbitrary command execution.
How do I fix CVE-2025-56089?
To fix CVE-2025-56089, update the Ruijie M18 firmware to the latest version that addresses this vulnerability.
What causes the CVE-2025-56089 vulnerability?
CVE-2025-56089 is caused by improper input validation in the module_set, allowing OS command injection via crafted POST requests.
What systems are affected by CVE-2025-56089?
CVE-2025-56089 affects the Ruijie M18 devices running specific versions of the EW_3.0 firmware.
How can an attacker exploit CVE-2025-56089?
An attacker can exploit CVE-2025-56089 by sending a specially crafted POST request to execute arbitrary commands on the device.