CVE-2025-56108: Command Injection
Published Dec 11, 2025
·Updated
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V109241521 allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua.
Affected Software
11 affected components
Ruijie X30-PRO
All of the following
Ruijie X30 Pro Firmware
Ruijie X30 PRO=1.0
All of the following
Ruijie Rg-eap602 Firmware=3.0\(1\)b2p55
Ruijie Rg-eap602
All of the following
Ruijie Rg-est350 Firmware=3.0\(1\)b11p221
Ruijie Rg-est350=2.0
All of the following
Ruijie Rg-ew300 Pro Firmware=3.0\(1\)b11p219
Ruijie Rg-ew300 Pro
All of the following
Ruijie Rg-est310 Firmware=3.0\(1\)b11p211
Ruijie Rg-est310=2.0
Event History
Dec 11, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56108?
CVE-2025-56108 has a high severity rating due to its ability to allow arbitrary command execution.
2
How do I fix CVE-2025-56108?
To fix CVE-2025-56108, update to the latest firmware version provided by Ruijie for the X30-PRO.
3
What products are affected by CVE-2025-56108?
CVE-2025-56108 affects the Ruijie X30-PRO model.
4
What type of vulnerability is CVE-2025-56108?
CVE-2025-56108 is an OS Command Injection vulnerability.
5
How does CVE-2025-56108 exploit the system?
CVE-2025-56108 exploits the system by allowing attackers to execute commands via a crafted POST request.