CVE-2025-56113: Command Injection
OS Command Injection vulnerability in Ruijie RG-YST EST, YSTAP3.0(1)B11P280YST250F V1.xxV2.xx allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-56113?
CVE-2025-56113 is considered a critical vulnerability due to its potential to allow arbitrary command execution.
How do I fix CVE-2025-56113?
To mitigate CVE-2025-56113, update the Ruijie RG-YST EST software to a version that addresses this command injection vulnerability.
What types of attacks can be executed through CVE-2025-56113?
CVE-2025-56113 enables attackers to execute arbitrary operating system commands, potentially compromising the affected system.
Which versions of Ruijie RG-YST EST are affected by CVE-2025-56113?
Versions from YSTAP_3.0(1)B11P280YST250F to V2.xx are affected by CVE-2025-56113.
Is there any known exploit for CVE-2025-56113?
Yes, there are known exploits for CVE-2025-56113 that can be executed via crafted POST requests.