CVE-2025-56114: Command Injection
OS Command Injection vulnerability in Ruijie M18 EW3.0(1)B11P226M1810223116 allowing attackers to execute arbitrary commands via a crafted POST request to the moduleset in file /usr/local/lua/devconfig/configretain.lua.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-56114?
CVE-2025-56114 is classified as a critical vulnerability due to the potential for arbitrary command execution.
How does CVE-2025-56114 affect the Ruijie M18 EW_3.0(1)B11P226?
CVE-2025-56114 allows attackers to execute arbitrary commands through a crafted POST request to the module_set endpoint.
What versions of Ruijie M18 EW are affected by CVE-2025-56114?
CVE-2025-56114 specifically affects Ruijie M18 EW_3.0(1)B11P226.
How can I mitigate CVE-2025-56114?
To mitigate CVE-2025-56114, ensure that your Ruijie M18 firmware is updated to the latest secure version.
What action should I take if I suspect exploitation of CVE-2025-56114?
If you suspect exploitation of CVE-2025-56114, immediately review logs, isolate the affected system, and update it to close the vulnerability.