CVE-2025-56107: Command Injection
Published Dec 11, 2025
·Updated
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the submitwifi in file /usr/lib/lua/luci/controller/admin/commonquickconfig.lua.
Affected Software
3 affected components
Ruijie RG-BCR600W
All of the following
Ruijie Rg-bcr600w Firmware
Ruijie RG-BCR600W
Event History
Dec 11, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56107?
CVE-2025-56107 is classified as a high severity OS Command Injection vulnerability.
2
How do I fix CVE-2025-56107?
To fix CVE-2025-56107, apply the latest firmware updates provided by Ruijie for the RG-BCR600W.
3
What are the potential impacts of CVE-2025-56107?
The potential impacts of CVE-2025-56107 include unauthorized remote command execution, leading to complete system compromise.
4
Who is affected by CVE-2025-56107?
CVE-2025-56107 affects users of the Ruijie RG-BCR600W device.
5
How does CVE-2025-56107 exploit the system?
CVE-2025-56107 allows attackers to exploit the system by sending a specially crafted POST request to the device.