CVE-2025-56111: Command Injection
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the networksetwanconf in file /usr/lib/lua/luci/controller/admin/netport.lua.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-56111?
CVE-2025-56111 has been classified as a critical severity vulnerability due to its potential for arbitrary command execution.
How do I fix CVE-2025-56111?
To remediate CVE-2025-56111, update the Ruijie RG-BCR860 firmware to version 2.5.13-r2225 or later.
What is the impact of CVE-2025-56111?
CVE-2025-56111 allows attackers to execute arbitrary commands on the device, potentially compromising the network.
Which devices are affected by CVE-2025-56111?
The Ruijie RG-BCR860 running firmware version 2.5.13-r2224 is affected by CVE-2025-56111.
Is there a workaround for CVE-2025-56111 before applying a patch?
To temporarily mitigate CVE-2025-56111, consider blocking network access to vulnerable endpoints until the firmware is updated.