CVE-2025-56096: Command Injection
Published Dec 11, 2025
·Updated
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the restartmodules in file /usr/lib/lua/luci/controller/admin/common.lua.
Affected Software
3 affected components
Ruijie RG-BCR600W
All of the following
Ruijie Rg-bcr600w Firmware
Ruijie RG-BCR600W
Event History
Dec 11, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56096?
The CVE-2025-56096 vulnerability has a high severity rating due to the potential for remote command execution.
2
How do I fix CVE-2025-56096?
To fix CVE-2025-56096, apply the latest firmware update provided by Ruijie for the RG-BCR600W.
3
What kind of attacks can exploit CVE-2025-56096?
CVE-2025-56096 can be exploited through crafted POST requests that allow arbitrary OS command execution.
4
Who is affected by CVE-2025-56096?
CVE-2025-56096 affects users of the Ruijie RG-BCR600W device.
5
What is the vector for CVE-2025-56096?
The attack vector for CVE-2025-56096 is remote and can be initiated through a network connection.