CVE-2025-56094: Command Injection
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V109241521 allowing attackers to execute arbitrary commands via a crafted POST request to the moduleget in file /usr/local/lua/devsta/hostaccessdelay.lua.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-56094?
CVE-2025-56094 is classified as a critical vulnerability due to its potential for remote command execution.
How do I fix CVE-2025-56094?
To mitigate CVE-2025-56094, it is recommended to update the Ruijie X30-PRO firmware to the latest version provided by the vendor.
What systems are affected by CVE-2025-56094?
CVE-2025-56094 specifically affects the Ruijie X30-PRO model running the specified firmware version.
What type of vulnerability is CVE-2025-56094?
CVE-2025-56094 is an OS Command Injection vulnerability allowing attackers to execute arbitrary commands.
How can attackers exploit CVE-2025-56094?
Attackers can exploit CVE-2025-56094 by sending a crafted POST request to the module_get endpoint in a specific Lua file.