CVE-2025-56095: Command Injection
OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the moduleset in file /usr/local/lua/devsta/nbrcwmp.lua.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-56095?
CVE-2025-56095 is classified as a critical severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-56095?
To fix CVE-2025-56095, it is recommended to update the Ruijie RG-EW1200G PRO to the latest firmware version that addresses this vulnerability.
Who is affected by CVE-2025-56095?
CVE-2025-56095 affects users of the Ruijie RG-EW1200G PRO models running firmware versions V1.00 through V4.00.
What impact does CVE-2025-56095 have?
CVE-2025-56095 allows an attacker to execute arbitrary OS commands, potentially compromising the device and its network.
Is there a patch available for CVE-2025-56095?
Yes, a patch addressing CVE-2025-56095 is included in the latest firmware update from Ruijie.